<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T06:26:09.850-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:29004" version="3" class="patch">
      <metadata>
        <title>ELSA-2015-0998 -- Oracle qemu-kvm_qemu-guest-agent</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
          <product>qemu-guest-agent</product>
        </affected>
        <reference source="VENDOR" ref_url="https://oss.oracle.com/pipermail/el-errata/2015-May/005068.html" ref_id="ELSA-2015-0998"/>
        <reference source="CVE" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456" ref_id="CVE-2015-3456"/>
        <description>KVM  is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the user-space component for running virtual machines using KVM. An out-of-bounds memory access flaw was found in the way QEMU"s virtual Floppy Disk Controller  handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the host"s QEMU process corresponding to the guest.  Red Hat would like to thank Jason Geffner of CrowdStrike for reporting this issue. All qemu-kvm users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-02T09:04:27-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-03T12:26:54.858-04:00">DRAFT</status_change>
            <status_change date="2015-06-22T04:00:45.017-04:00">INTERIM</status_change>
            <status_change date="2015-07-13T04:00:15.795-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Package Section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.448.el6_6.3 for x86_64" test_ref="oval:org.mitre.oval:tst:138899"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.448.el6_6.3 for x86_64" test_ref="oval:org.mitre.oval:tst:138864"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.448.el6_6.3 for i686" test_ref="oval:org.mitre.oval:tst:138656"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.448.el6_6.3 for x86_64" test_ref="oval:org.mitre.oval:tst:138768"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28647" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3108 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3108.html" ref_id="ELSA-2014-3108"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6657" ref_id="CVE-2012-6657"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5471" ref_id="CVE-2014-5471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5472" ref_id="CVE-2014-5472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9090" ref_id="CVE-2014-9090"/>
        <description>kernel-uek [2.6.32-400.36.13uek] - net: guard tcp_set_keepalive() to tcp
          sockets (Eric Dumazet) [Orabug: 20224099] {CVE-2012-6657} - isofs: Fix unbounded recursion
          when processing relocated directories (Jan Kara) [Orabug: 20224061] {CVE-2014-5471}
          {CVE-2014-5472} - x86_64, traps: Stop using IST for #SS (Andy Lutomirski) [Orabug:
          20224029] {CVE-2014-9090} {CVE-2014-9322}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:24.291-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:35.492-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:31.717-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136785 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:52.836-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:55.958-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136790"/>
            <criterion comment="mlnx_en-2.6.32-400.36.13.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:136715"/>
            <criterion comment="ofa-2.6.32-400.36.13.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136763"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136345"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136837"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136775"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136282"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136696"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.13.el5uek" test_ref="oval:org.mitre.oval:tst:136720"/>
            <criterion comment="mlnx_en-2.6.32-400.36.13.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:136688"/>
            <criterion comment="ofa-2.6.32-400.36.13.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136141"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136565"/>
            <criterion comment="mlnx_en-2.6.32-400.36.13.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:136785"/>
            <criterion comment="ofa-2.6.32-400.36.13.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136704"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136346"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136677"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136599"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:135876"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136687"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.13.el6uek" test_ref="oval:org.mitre.oval:tst:136699"/>
            <criterion comment="mlnx_en-2.6.32-400.36.13.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:136061"/>
            <criterion comment="ofa-2.6.32-400.36.13.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28643" version="3" class="patch">
      <metadata>
        <title>ELSA-2015-1115 -- Oracle openssl</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="https://oss.oracle.com/pipermail/el-errata/2015-June/005125.html" ref_id="ELSA-2015-1115"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1791" ref_id="CVE-2015-1791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0209" ref_id="CVE-2015-0209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8176" ref_id="CVE-2014-8176"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1789" ref_id="CVE-2015-1789"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1790" ref_id="CVE-2015-1790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1792" ref_id="CVE-2015-1792"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3216" ref_id="CVE-2015-3216"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer  and Transport Layer Security  protocols, as well as a full-strength, general purpose cryptography library. An invalid free flaw was found in the way OpenSSL handled certain DTLS handshake messages. A malicious DTLS client or server could cause a DTLS server or client using OpenSSL to crash or, potentially, execute arbitrary code.  A flaw was found in the way the OpenSSL packages shipped with Red Hat Enterprise Linux 6 and 7 performed locking in the ssleay_rand_bytes function. This issue could possibly cause a multi-threaded application using OpenSSL to perform an out-of-bounds read and crash.  An out-of-bounds read flaw was found in the X509_cmp_time function of OpenSSL. A specially crafted X.509 certificate or a Certificate Revocation List  could possibly cause a TLS/SSL server or client using OpenSSL to crash.  A race condition was found in the session handling code of OpenSSL. This issue could possibly cause a multi-threaded TLS/SSL client using OpenSSL to double free session ticket data and crash.  A flaw was found in the way OpenSSL handled Cryptographic Message Syntax  messages. A CMS message with an unknown hash function identifier could cause an application using OpenSSL to enter an infinite loop.  A NULL pointer dereference was found in the way OpenSSL handled certain PKCS#7 inputs. A specially crafted PKCS#7 input with missing EncryptedContent data could cause an application using OpenSSL to crash.  Red Hat would like to thank the OpenSSL project for reporting CVE-2014-8176, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791 and CVE-2015-1792 flaws. Upstream acknowledges Praveen Kariyanahalli and Ivan Fratric as the original reporters of CVE-2014-8176, Robert Swiecki and Hanno Bock as the original reporters of CVE-2015-1789, Michal Zalewski as the original reporter of CVE-2015-1790, Emilia Kasper as the original report of CVE-2015-1791 and Johannes Bauer as the original reporter of CVE-2015-1792. All openssl users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T09:20:00-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T09:29:47.951-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:18.739-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:24.495-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="All dependent packages of openssl">
          <criterion comment="openssl is earlier than 0:1.0.1e-30.el6_6.11 for i686" test_ref="oval:org.mitre.oval:tst:138647"/>
          <criterion comment="openssl-devel is earlier than 0:1.0.1e-30.el6_6.11 for i686" test_ref="oval:org.mitre.oval:tst:138021"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.1e-30.el6_6.11 for i686" test_ref="oval:org.mitre.oval:tst:138997"/>
          <criterion comment="openssl-static is earlier than 0:1.0.1e-30.el6_6.11 for i686" test_ref="oval:org.mitre.oval:tst:138548"/>
          <criterion comment="openssl is earlier than 0:1.0.1e-30.el6_6.11 for x86_64" test_ref="oval:org.mitre.oval:tst:138674"/>
          <criterion comment="openssl-devel is earlier than 0:1.0.1e-30.el6_6.11 for x86_64" test_ref="oval:org.mitre.oval:tst:138445"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.1e-30.el6_6.11 for x86_64" test_ref="oval:org.mitre.oval:tst:138995"/>
          <criterion comment="openssl-static is earlier than 0:1.0.1e-30.el6_6.11 for x86_64" test_ref="oval:org.mitre.oval:tst:138809"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28622" version="3" class="patch">
      <metadata>
        <title>ELSA-2015-0092 -- glibc security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2015-0092.html" ref_id="ELSA-2015-0092"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235" ref_id="CVE-2015-0235"/>
        <description>[2.17-55.0.4.el7_0.5]
- Remove strstr and strcasestr implementations using sse4.2 instructions.
- Upstream commits 584b18eb4df61ccd447db2dfe8c8a7901f8c8598 and
  1818483b15d22016b0eae41d37ee91cc87b37510 backported. (Jose E. Marchesi)

[2.17-55.5]
- Rebuild and run regression testing.

[2.17-55.4]
- Fix parsing of numeric hosts in gethostbyname_r (CVE-2015-0235, #1183535).

[2.17-55.3]
- Fix wordexp() to honour WRDE_NOCMD (CVE-2014-7817, #1170118)

[2.17-55.2]
- ftell: seek to end only when there are unflushed bytes (#1170187).

[2.17-55.1]
- Remove gconv transliteration loadable modules support (CVE-2014-5119,
  - _nl_find_locale: Improve handling of crafted locale names (CVE-2014-0475,</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-28T12:52:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-29T16:29:59.040-05:00">DRAFT</status_change>
            <status_change date="2015-02-16T04:00:09.444-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:46.849-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137271"/>
            <criterion comment="glibc-common is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137406"/>
            <criterion comment="glibc-devel is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137663"/>
            <criterion comment="glibc-headers is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137470"/>
            <criterion comment="glibc-static is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137439"/>
            <criterion comment="glibc-utils is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137591"/>
            <criterion comment="nscd is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137287"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.17-55.0.4.el7_0.5" test_ref="oval:org.mitre.oval:tst:137257"/>
            <criterion comment="glibc-common is earlier than 0:2.17-55.0.4.el7_0.5" test_ref="oval:org.mitre.oval:tst:137616"/>
            <criterion comment="glibc-devel is earlier than 0:2.17-55.0.4.el7_0.5" test_ref="oval:org.mitre.oval:tst:137415"/>
            <criterion comment="glibc-headers is earlier than 0:2.17-55.0.4.el7_0.5" test_ref="oval:org.mitre.oval:tst:137419"/>
            <criterion comment="glibc-static is earlier than 0:2.17-55.0.4.el7_0.5" test_ref="oval:org.mitre.oval:tst:137344"/>
            <criterion comment="glibc-utils is earlier than 0:2.17-55.0.4.el7_0.5" test_ref="oval:org.mitre.oval:tst:137316"/>
            <criterion comment="nscd is earlier than 0:2.17-55.0.4.el7_0.5" test_ref="oval:org.mitre.oval:tst:137641"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28612" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1997 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1997.html" ref_id="ELSA-2014-1997"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3687" ref_id="CVE-2014-3687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3673" ref_id="CVE-2014-3673"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3688" ref_id="CVE-2014-3688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6410" ref_id="CVE-2014-6410"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6657" ref_id="CVE-2012-6657"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5471" ref_id="CVE-2014-5471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5472" ref_id="CVE-2014-5472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <description>[2.6.32-504.3.3]
- [x86] traps: stop using IST for #SS (Petr  Matousek) [1172810 1172811] {CVE-2014-9322}

[2.6.32-504.3.2]
- [md] dm-thin: fix pool_io_hints to avoid looking at max_hw_sectors (Mike Snitzer) [1161420 1161421 1142773 1145230]

[2.6.32-504.3.1]
- [s390] zcrypt: toleration of new crypto adapter hardware (Hendrik Brueckner) [1158311 1134984]
- [s390] zcrypt: support for extended number of ap domains (Hendrik Brueckner) [1158311 1134984]
- [md] dm-thin: fix potential for infinite loop in pool_io_hints (Mike Snitzer) [1161420 1161421 1142773 1145230]

[2.6.32-504.2.1]
- [fs] udf: Avoid infinite loop when processing indirect ICBs (Jacob Tanenbaum) [1142319 1142320] {CVE-2014-6410}
- [fs] isofs: unbound recursion when processing relocated directories (Jacob Tanenbaum) [1142268 1142269] {CVE-2014-5472 CVE-2014-5471}
- [net] ipv6: delete expired route in ip6_pmtu_deliver (Hannes Frederic Sowa) [1161418 1156137]
- [net] sctp: fix remote memory pressure from excessive queueing (Daniel Borkmann) [1155746 1154676] {CVE-2014-3688}
- [net] sctp: fix panic on duplicate ASCONF chunks (Daniel Borkmann) [1155733 1154676] {CVE-2014-3687}
- [net] sctp: fix skb_over_panic when receiving malformed ASCONF chunks (Daniel Borkmann) [1147857 1154676] {CVE-2014-3673}
- [net] sctp: handle association restarts when the socket is closed (Daniel Borkmann) [1147857 1154676]
- [md] dm-thin: refactor requeue_io to eliminate spinlock bouncing (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: optimize retry_bios_on_resume (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: sort the deferred cells (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: direct dispatch when breaking sharing (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: remap the bios in a cell immediately (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: defer whole cells rather than individual bios (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: factor out remap_and_issue_overwrite (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: performance improvement to discard processing (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: grab a virtual cell before looking up the mapping (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: implement thin_merge (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm: improve documentation and code clarity in dm_merge_bvec (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: adjust max_sectors_kb based on thinp blocksize (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] block: fix alignment_offset math that assumes io_min is a power-of-2 (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: throttle incoming IO (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: prefetch missing metadata pages (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-transaction-manager: add support for prefetching blocks of metadata (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin-metadata: change dm_thin_find_block to allow blocking, but not issuing, IO (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-bio-prison: switch to using a red black tree (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-bufio: evict buffers that are past the max age but retain some buffers (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-bufio: switch from a huge hash table to an rbtree (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-bufio: update last_accessed when relinking a buffer (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-bufio: use kzalloc when allocating dm_bufio_client (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin-metadata: do not allow the data block size to change (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: cleanup noflush_work to use a proper completion (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [md] dm-thin: fix DMERR typo in pool_status error path (Mike Snitzer) [1161420 1161421 1142773 1145230]
- [fs] xfs: xlog_cil_force_lsn doesn't always wait correctly (Eric Sandeen) [1158325 1133304]
- [netdrv] ixgbe: allow TXDCTL.WRTHRESH to be 1 will small ITR values (John Greene) [1158326 1132267]
- [netdrv] ixgbe: Intel Change to allow itr changes without CONFIG_BQL support (John Greene) [1158326 1132267]
- [video] offb: Fix setting of the pseudo-palette for >8bpp (Gerd Hoffmann) [1158328 1142450]
- [video] offb: Add palette hack for qemu 'standard vga' framebuffer (Gerd Hoffmann) [1158328 1142450]
- [video] offb: Fix bug in calculating requested vram size (Gerd Hoffmann) [1158328 1142450]
- [net] sock_queue_err_skb() dont mess with sk_forward_alloc (Jiri Benc) [1155427 1148257]
- [net] guard tcp_set_keepalive() to tcp sockets (Florian Westphal) [1141744 1141746] {CVE-2012-6657}
- Revert: [net] revert 'bridge: Set vlan_features to allow offloads on vlans' (Vlad Yasevich) [1144442 1121991]
- [x86] kvm: fix PIT timer race condition (mguzik) [1149592 1149593] {CVE-2014-3611}
- [x86] kvm: vmx: handle invept and invvpid vm exits gracefull (mguzik) [1144826 1144837 1144827 1144838] {CVE-2014-3646 CVE-2014-3645}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:34.550-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:33.509-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:30.127-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136917"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136874"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136910"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136849"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136851"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136927"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136574"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136583"/>
          <criterion comment="perf is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136676"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136902"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28543" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1983 -- xorg-x11-server security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1983.html" ref_id="ELSA-2014-1983"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8091" ref_id="CVE-2014-8091"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8092" ref_id="CVE-2014-8092"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8093" ref_id="CVE-2014-8093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8094" ref_id="CVE-2014-8094"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8095" ref_id="CVE-2014-8095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8096" ref_id="CVE-2014-8096"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8097" ref_id="CVE-2014-8097"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8098" ref_id="CVE-2014-8098"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8099" ref_id="CVE-2014-8099"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8100" ref_id="CVE-2014-8100"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8101" ref_id="CVE-2014-8101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8102" ref_id="CVE-2014-8102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8103" ref_id="CVE-2014-8103"/>
        <description>[1.15.0-7.0.1.el7_0.3]
- Invalid BUG_RETURN_VAL fix, upstream patch (orabug 18896390)

[1.15.0-7.3]
- CVE fixes for: CVE-2014-8099, CVE-2014-8098, CVE-2014-8097, CVE-2014-8096,
  CVE-2014-8095, CVE-2014-8094, CVE-2014-8093, CVE-2014-8092, CVE-2014-8091,
  CVE-2014-8101, CVE-2014-8100, CVE-2014-8103, CVE-2014-8102</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:18.264-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:30.412-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:27.169-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:137042"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:136046"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:136999"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:136724"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:136934"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:136987"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:136817"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:136866"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:136219"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.15.0-7.0.1.el7_0.3" test_ref="oval:org.mitre.oval:tst:136915"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.15.0-7.0.1.el7_0.3" test_ref="oval:org.mitre.oval:tst:136771"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.15.0-7.0.1.el7_0.3" test_ref="oval:org.mitre.oval:tst:136737"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.15.0-7.0.1.el7_0.3" test_ref="oval:org.mitre.oval:tst:136047"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.15.0-7.0.1.el7_0.3" test_ref="oval:org.mitre.oval:tst:136620"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.15.0-7.0.1.el7_0.3" test_ref="oval:org.mitre.oval:tst:136850"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.15.0-7.0.1.el7_0.3" test_ref="oval:org.mitre.oval:tst:136949"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.15.0-7.0.1.el7_0.3" test_ref="oval:org.mitre.oval:tst:136108"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.15.0-7.0.1.el7_0.3" test_ref="oval:org.mitre.oval:tst:137017"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28492" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3107 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3107.html" ref_id="ELSA-2014-3107"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5471" ref_id="CVE-2014-5471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5472" ref_id="CVE-2014-5472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9090" ref_id="CVE-2014-9090"/>
        <description>[2.6.39-400.215.15]
- isofs: Fix unbounded recursion when processing relocated directories (Jan Kara)  [Orabug: 20224060]  {CVE-2014-5471} {CVE-2014-5472}
- x86_64, traps: Stop using IST for #SS (Andy Lutomirski)  [Orabug: 20224028]  {CVE-2014-9090} {CVE-2014-9322}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:33.730-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:27.021-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:24.239-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136832"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136942"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136702"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136622"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136912"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.15.el5uek" test_ref="oval:org.mitre.oval:tst:136881"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136963"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136731"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136952"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136779"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136569"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.15.el6uek" test_ref="oval:org.mitre.oval:tst:136803"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28485" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1984 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1984.html" ref_id="ELSA-2014-1984"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8500" ref_id="CVE-2014-8500"/>
        <description>[32:9.9.4-14.0.1.el7_0.1]
- Rebuild to fix libmysqlclient dependency

[32:9.9.4-14.1]
- Fix CVE-2014-8500 (#1171975)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:29.231-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:26.375-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136873 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-23T04:01:23.618-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136036"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136519"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136733"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136925"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137016"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136706"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136834"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136780"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136873"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136911"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136996"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136814"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137028"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136918"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136935"/>
            <criterion comment="bind-chroot is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136900"/>
            <criterion comment="bind-devel is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136970"/>
            <criterion comment="bind-libs is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:137036"/>
            <criterion comment="bind-libs-lite is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136916"/>
            <criterion comment="bind-license is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136571"/>
            <criterion comment="bind-lite-devel is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:137037"/>
            <criterion comment="bind-sdb is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136892"/>
            <criterion comment="bind-sdb-chroot is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:137014"/>
            <criterion comment="bind-utils is earlier than 32:9.9.4-14.0.1.el7_0.1" test_ref="oval:org.mitre.oval:tst:136975"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28482" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3104 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3104.html" ref_id="ELSA-2014-3104"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3181" ref_id="CVE-2014-3181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1739" ref_id="CVE-2014-1739"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3186" ref_id="CVE-2014-3186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3688" ref_id="CVE-2014-3688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4027" ref_id="CVE-2014-4027"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4652" ref_id="CVE-2014-4652"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4656" ref_id="CVE-2014-4656"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6410" ref_id="CVE-2014-6410"/>
        <description>[2.6.39-400.215.14] 

- HID: magicmouse: sanity check report size in raw_event() callback (Jiri Kosina) [Orabug: 19849355] {CVE-2014-3181} 

- ALSA: control: Protect user controls against concurrent access (Lars-Peter Clausen) [Orabug: 20192542] {CVE-2014-4652} 

- target/rd: Refactor rd_build_device_space + rd_release_device_space (Nicholas Bellinger) [Orabug: 20192517] {CVE-2014-4027} 

- media-device: fix infoleak in ioctl media_enum_entities() (Salva Peiro) [Orabug: 20192501] {CVE-2014-1739} {CVE-2014-1739} 

- udf: Avoid infinite loop when processing indirect ICBs (Jan Kara) [Orabug: 20192449] {CVE-2014-6410} 

- ALSA: control: Make sure that id->index does not overflow (Lars-Peter Clausen) [Orabug: 20192418] {CVE-2014-4656} 

- ALSA: control: Handle numid overflow (Lars-Peter Clausen) [Orabug: 20192376] {CVE-2014-465} 

- HID: picolcd: sanity check report size in raw_event() callback (Jiri Kosina) [Orabug: 20192205] {CVE-2014-3186} 

- net: sctp: fix remote memory pressure from excessive queueing (Daniel Borkmann) [Orabug: 20192059] {CVE-2014-3688}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:22.194-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:25.820-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:23.251-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:136810"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:136904"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:136042"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:137030"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:137027"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.14.el5uek" test_ref="oval:org.mitre.oval:tst:136821"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:137031"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:136972"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:137007"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:136533"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:136974"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.14.el6uek" test_ref="oval:org.mitre.oval:tst:136883"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28420" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-2021 -- jasper security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>jasper</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-2021.html" ref_id="ELSA-2014-2021"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8137" ref_id="CVE-2014-8137"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8138" ref_id="CVE-2014-8138"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9029" ref_id="CVE-2014-9029"/>
        <description>[1.900.1-16.2]
- CVE-2014-8137 - double-free in in jas_iccattrval_destroy (#1173566)
- CVE-2014-8138 - heap overflow in jp2_decode (#1173566)

[1.900.1-16.1]
- CVE-2014-9029 - incorrect component number check in COC, RGN and QCC
                  marker segment decoders (#1171208)

[1.900.1-16]
- CERT VU#887409: heap buffer overflow flaws lead to arbitrary code execution
  (#749150)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:28.273-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:22.347-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:20.335-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jasper is earlier than 0:1.900.1-16.el6_6.2" test_ref="oval:org.mitre.oval:tst:136509"/>
            <criterion comment="jasper-devel is earlier than 0:1.900.1-16.el6_6.2" test_ref="oval:org.mitre.oval:tst:136818"/>
            <criterion comment="jasper-libs is earlier than 0:1.900.1-16.el6_6.2" test_ref="oval:org.mitre.oval:tst:136936"/>
            <criterion comment="jasper-utils is earlier than 0:1.900.1-16.el6_6.2" test_ref="oval:org.mitre.oval:tst:136894"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jasper is earlier than 0:1.900.1-26.el7_0.2" test_ref="oval:org.mitre.oval:tst:136403"/>
            <criterion comment="jasper-devel is earlier than 0:1.900.1-26.el7_0.2" test_ref="oval:org.mitre.oval:tst:136843"/>
            <criterion comment="jasper-libs is earlier than 0:1.900.1-26.el7_0.2" test_ref="oval:org.mitre.oval:tst:136691"/>
            <criterion comment="jasper-utils is earlier than 0:1.900.1-26.el7_0.2" test_ref="oval:org.mitre.oval:tst:136769"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28393" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1870 -- libXfont security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1870.html" ref_id="ELSA-2014-1870"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0209" ref_id="CVE-2014-0209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0210" ref_id="CVE-2014-0210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0211" ref_id="CVE-2014-0211"/>
        <description>[1.4.5-4]
- CVE-2014-0209: integer overflow of allocations in font metadata file parsing (bug 1163602, bug 1163601)
- CVE-2014-0210: unvalidated length fields when parsing xfs protocol replies (bug 1163602, bug 1163601)
- CVE-2014-0211: integer overflows calculating memory needs for xfs replies (bug 1163602, bug 1163601)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:27.057-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:38.774-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:41.325-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.4.5-4.el6_6" test_ref="oval:org.mitre.oval:tst:135893"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-4.el6_6" test_ref="oval:org.mitre.oval:tst:135704"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.4.7-2.el7_0" test_ref="oval:org.mitre.oval:tst:135910"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.7-2.el7_0" test_ref="oval:org.mitre.oval:tst:135620"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28378" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1873 -- libvirt security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1873.html" ref_id="ELSA-2014-1873"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3633" ref_id="CVE-2014-3633"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3657" ref_id="CVE-2014-3657"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7823" ref_id="CVE-2014-7823"/>
        <description>[0.10.2-46.0.1.el6_6.2]
- Replace docs/et.png in tarball with blank image

[0.10.2-46.el6_6.2]
- qemu: allow restore with non-migratable XML input (rhbz#1155564)
- qemu: Introduce qemuDomainDefCheckABIStability (rhbz#1155564)
- Make ABI stability issue easier to debug (rhbz#1155564)
- CVE-2014-3633: qemu: blkiotune: Use correct definition when looking up disk (CVE-2014-3633)
- domain_conf: fix domain deadlock (CVE-2014-3657)
- CVE-2014-7823: dumpxml: security hole with migratable flag (CVE-2014-7823)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:31.029-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:38.134-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:40.627-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.10.2-46.0.1.el6_6.2" test_ref="oval:org.mitre.oval:tst:136009"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-46.0.1.el6_6.2" test_ref="oval:org.mitre.oval:tst:135949"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-46.0.1.el6_6.2" test_ref="oval:org.mitre.oval:tst:135675"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-46.0.1.el6_6.2" test_ref="oval:org.mitre.oval:tst:135974"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-46.0.1.el6_6.2" test_ref="oval:org.mitre.oval:tst:135954"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28373" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3096 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3096.html" ref_id="ELSA-2014-3096"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3184" ref_id="CVE-2014-3184"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4014" ref_id="CVE-2014-4014"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1739" ref_id="CVE-2014-1739"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4171" ref_id="CVE-2014-4171"/>
        <description>Unbreakable Enterprise kernel security update</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:21.401-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:37.039-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:39.791-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28373 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:53.587-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:51.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dtrace-modules-3.8.13-55.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:135880"/>
            <criterion comment="kernel-uek is earlier than 0:3.8.13-55.el6uek" test_ref="oval:org.mitre.oval:tst:135708"/>
            <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-55.el6uek" test_ref="oval:org.mitre.oval:tst:135889"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-55.el6uek" test_ref="oval:org.mitre.oval:tst:135734"/>
            <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-55.el6uek" test_ref="oval:org.mitre.oval:tst:135788"/>
            <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-55.el6uek" test_ref="oval:org.mitre.oval:tst:135060"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-55.el6uek" test_ref="oval:org.mitre.oval:tst:136006"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dtrace-modules-3.8.13-55.el7uek is earlier than 0:0.4.3-4.el7" test_ref="oval:org.mitre.oval:tst:135678"/>
            <criterion comment="kernel-uek is earlier than 0:3.8.13-55.el7uek" test_ref="oval:org.mitre.oval:tst:135772"/>
            <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-55.el7uek" test_ref="oval:org.mitre.oval:tst:135866"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-55.el7uek" test_ref="oval:org.mitre.oval:tst:135907"/>
            <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-55.el7uek" test_ref="oval:org.mitre.oval:tst:135981"/>
            <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-55.el7uek" test_ref="oval:org.mitre.oval:tst:135712"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-55.el7uek" test_ref="oval:org.mitre.oval:tst:135994"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28324" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1999 -- mailx security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>mailx</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1999.html" ref_id="ELSA-2014-1999"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2771" ref_id="CVE-2004-2771"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7844" ref_id="CVE-2014-7844"/>
        <description>[12.4-8]
- CVE-2004-2771 mailx: command execution flaw
  resolves: #1171175</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:31.729-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:19.100-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:16.059-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="mailx is earlier than 0:12.4-8.el6_6" test_ref="oval:org.mitre.oval:tst:136650"/>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criterion comment="mailx is earlier than 0:12.5-12.el7_0" test_ref="oval:org.mitre.oval:tst:136876"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28316" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1826 -- libvncserver security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>libvncserver</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1826.html" ref_id="ELSA-2014-1826"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6051" ref_id="CVE-2014-6051"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6052" ref_id="CVE-2014-6052"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6053" ref_id="CVE-2014-6053"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6054" ref_id="CVE-2014-6054"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6055" ref_id="CVE-2014-6055"/>
        <description>[0.9.7-7.1]
- Fix CVE-2014-6051 (integer overflow in screen size handling) (bug #1157668)
- Fix CVE-2014-6052 (NULL pointer dereference in framebuffer setup)
  (bug #1157668)
- Fix CVE-2014-6053 (NULL pointer dereference in ClientCutText message
  handling) (bug #1157668)
- Fix CVE-2014-6054 (server divide-by-zero in scaling factor handling)
  (bug #1157668)
- Fix CVE-2014-6055 (server stacked-based buffer overflow in file transfer
  handling) (bug #1157668)

[0.9.7-7]
- Revert CVE-2011-0904 and CVE-2011-0905 patch because libvncserver is not
  vulnerable (bug #696767)

[0.9.7-6]
- Fix CVE-2011-0904 and CVE-2011-0905 in more generic way (bug #696767)

[0.9.7-5]
- Fix CVE-2011-0904 (bug #696767)
- Fix CVE-2011-0905 (bug #696767)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:10:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-17T19:58:43.720-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:03.308-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:45.416-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvncserver is earlier than 0:0.9.7-7.el6_6.1" test_ref="oval:org.mitre.oval:tst:135552"/>
            <criterion comment="libvncserver-devel is earlier than 0:0.9.7-7.el6_6.1" test_ref="oval:org.mitre.oval:tst:135613"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvncserver is earlier than 0:0.9.9-9.el7_0.1" test_ref="oval:org.mitre.oval:tst:135218"/>
            <criterion comment="libvncserver-devel is earlier than 0:0.9.9-9.el7_0.1" test_ref="oval:org.mitre.oval:tst:135510"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28309" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3088 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3088.html" ref_id="ELSA-2014-3088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3687" ref_id="CVE-2014-3687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3673" ref_id="CVE-2014-3673"/>
        <description>[2.6.39-400.215.13]
- net: sctp: fix panic on duplicate ASCONF chunks (Daniel Borkmann)  [Orabug: 20010591]  {CVE-2014-3687}
- net: sctp: fix skb_over_panic when receiving malformed ASCONF chunks (Daniel Borkmann)  [Orabug: 20010578]  {CVE-2014-3673}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:10:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-17T19:58:42.844-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:03.180-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:45.056-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:135364"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:135579"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:134934"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:134717"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:135663"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.13.el5uek" test_ref="oval:org.mitre.oval:tst:135400"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135604"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135548"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135659"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135634"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135564"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.13.el6uek" test_ref="oval:org.mitre.oval:tst:135144"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28305" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3103 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3103.html" ref_id="ELSA-2014-3103"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3182" ref_id="CVE-2014-3182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3186" ref_id="CVE-2014-3186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3688" ref_id="CVE-2014-3688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4027" ref_id="CVE-2014-4027"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4652" ref_id="CVE-2014-4652"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4656" ref_id="CVE-2014-4656"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6410" ref_id="CVE-2014-6410"/>
        <description>kernel-uek [3.8.13-55.1.1] - ALSA: control: Protect user controls against
          concurrent access (Lars-Peter Clausen) [Orabug: 20192540] {CVE-2014-4652} - target/rd:
          Refactor rd_build_device_space + rd_release_device_space (Nicholas Bellinger) [Orabug:
          20192516] {CVE-2014-4027} - HID: logitech: perform bounds checking on device_id early
          enough (Jiri Kosina) [Orabug: 20192477] {CVE-2014-3182} - udf: Avoid infinite loop when
          processing indirect ICBs (Jan Kara) [Orabug: 20192448] {CVE-2014-6410} - ALSA: control:
          Make sure that id->index does not overflow (Lars-Peter Clausen) [Orabug: 20192416]
          {CVE-2014-4656} - ALSA: control: Handle numid overflow (Lars-Peter Clausen) [Orabug:
          20192367] {CVE-2014-4656} - HID: picolcd: sanity check report size in raw_event() callback
          (Jiri Kosina) [Orabug: 20192208] {CVE-2014-3186} - net: sctp: fix remote memory pressure
          from excessive queueing (Daniel Borkmann) [Orabug: 20192058] {CVE-2014-3688}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:17.072-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:18.347-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:15.061-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136940 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:53.229-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:50.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dtrace-modules-3.8.13-55.1.1.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:136940"/>
            <criterion comment="kernel-uek is earlier than 0:3.8.13-55.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:136730"/>
            <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-55.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:136969"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-55.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:137133"/>
            <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-55.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:136929"/>
            <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-55.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:137089"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-55.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:136966"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dtrace-modules-3.8.13-55.1.1.el7uek is earlier than 0:0.4.3-4.el7" test_ref="oval:org.mitre.oval:tst:136939"/>
            <criterion comment="kernel-uek is earlier than 0:3.8.13-55.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:136741"/>
            <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-55.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:136772"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-55.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:137041"/>
            <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-55.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:136430"/>
            <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-55.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:136742"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-55.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:136754"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28304" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-2024 -- ntp security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>ntp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-2024.html" ref_id="ELSA-2014-2024"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9293" ref_id="CVE-2014-9293"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9294" ref_id="CVE-2014-9294"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9295" ref_id="CVE-2014-9295"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9296" ref_id="CVE-2014-9296"/>
        <description>[4.2.6p5-2]
- don't generate weak control key for resolver (CVE-2014-9293)
- don't generate weak MD5 keys in ntp-keygen (CVE-2014-9294)
- fix buffer overflows via specially-crafted packets (CVE-2014-9295)
- don't mobilize passive association when authentication fails (CVE-2014-9296)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:11.521-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:18.146-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:14.919-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ntp is earlier than 0:4.2.6p5-2.el6_6" test_ref="oval:org.mitre.oval:tst:136484"/>
            <criterion comment="ntp-doc is earlier than 0:4.2.6p5-2.el6_6" test_ref="oval:org.mitre.oval:tst:136175"/>
            <criterion comment="ntp-perl is earlier than 0:4.2.6p5-2.el6_6" test_ref="oval:org.mitre.oval:tst:136816"/>
            <criterion comment="ntpdate is earlier than 0:4.2.6p5-2.el6_6" test_ref="oval:org.mitre.oval:tst:136679"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ntp is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:136759"/>
            <criterion comment="ntp-doc is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:136513"/>
            <criterion comment="ntp-perl is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:136581"/>
            <criterion comment="ntpdate is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:136658"/>
            <criterion comment="sntp is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:136689"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28281" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1803 -- mod_auth_mellon security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mod_auth_mellon</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1803.html" ref_id="ELSA-2014-1803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8566" ref_id="CVE-2014-8566"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8567" ref_id="CVE-2014-8567"/>
        <description>[0.8.0-3]
- CVE-2014-8566 CVE-2014-8567
- Resolves: bz1157283
- Resolves: bz1157956</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:10:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-17T19:58:41.312-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:01.883-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:42.333-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="mod_auth_mellon is earlier than 0:0.8.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:135362"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28261" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1974 -- rpm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1974.html" ref_id="ELSA-2014-1974"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6435" ref_id="CVE-2013-6435"/>
        <description>[4.4.2.3-36.0.1]
- Add missing files in /usr/share/doc/

[4.8.0-36]
- Fix warning when applying the patch for #1163057

[4.8.0-35]
- Fix race condidition where unchecked data is exposed in the file system
  (CVE-2013-6435)(#1163057)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:27.743-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:16.989-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:13.629-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rpm is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:137129"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:137144"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136804"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136907"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136988"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136610"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-36.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:136800"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rpm is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136992"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137134"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137118"/>
            <criterion comment="rpm-cron is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136805"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136823"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137097"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137051"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28254" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1924 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1924.html" ref_id="ELSA-2014-1924"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1587" ref_id="CVE-2014-1587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1590" ref_id="CVE-2014-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1592" ref_id="CVE-2014-1592"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1593" ref_id="CVE-2014-1593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1594" ref_id="CVE-2014-1594"/>
        <description>[31.3.0-1.0.1.el6_6]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[31.3.0-1]
- Update to 31.3.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:26.479-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:27.298-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:31.177-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:31.3.0-1.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135786"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28227" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3087 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3087.html" ref_id="ELSA-2014-3087"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3687" ref_id="CVE-2014-3687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3673" ref_id="CVE-2014-3673"/>
        <description>kernel-uek [3.8.13-44.1.5.el6uek] - net: sctp: fix panic on duplicate ASCONF
          chunks (Daniel Borkmann) [Orabug: 20010590] {CVE-2014-3687} - net: sctp: fix
          skb_over_panic when receiving malformed ASCONF chunks (Daniel Borkmann) [Orabug: 20010577]
          {CVE-2014-3673}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:10:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-17T19:58:39.512-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:59.719-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:37.909-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37205 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:56.440-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:50.129-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dtrace-modules-3.8.13-44.1.5.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:135033"/>
            <criterion comment="kernel-uek is earlier than 0:3.8.13-44.1.5.el6uek" test_ref="oval:org.mitre.oval:tst:135334"/>
            <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-44.1.5.el6uek" test_ref="oval:org.mitre.oval:tst:135352"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-44.1.5.el6uek" test_ref="oval:org.mitre.oval:tst:135410"/>
            <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-44.1.5.el6uek" test_ref="oval:org.mitre.oval:tst:135037"/>
            <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-44.1.5.el6uek" test_ref="oval:org.mitre.oval:tst:135523"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-44.1.5.el6uek" test_ref="oval:org.mitre.oval:tst:135399"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dtrace-modules-3.8.13-44.1.5.el7uek is earlier than 0:0.4.3-4.el7" test_ref="oval:org.mitre.oval:tst:135460"/>
            <criterion comment="kernel-uek is earlier than 0:3.8.13-44.1.5.el7uek" test_ref="oval:org.mitre.oval:tst:135592"/>
            <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-44.1.5.el7uek" test_ref="oval:org.mitre.oval:tst:135551"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-44.1.5.el7uek" test_ref="oval:org.mitre.oval:tst:135575"/>
            <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-44.1.5.el7uek" test_ref="oval:org.mitre.oval:tst:135305"/>
            <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-44.1.5.el7uek" test_ref="oval:org.mitre.oval:tst:135371"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-44.1.5.el7uek" test_ref="oval:org.mitre.oval:tst:135633"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28209" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0183 -- openoffice.org security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0183.html" ref_id="ELSA-2011-0183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3450" ref_id="CVE-2010-3450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3451" ref_id="CVE-2010-3451"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3452" ref_id="CVE-2010-3452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3453" ref_id="CVE-2010-3453"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3454" ref_id="CVE-2010-3454"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3689" ref_id="CVE-2010-3689"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4253" ref_id="CVE-2010-4253"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4643" ref_id="CVE-2010-4643"/>
        <description>[3.2.1-19.3.0.1.el6_0.5]
- Replaced RedHat colors with Oracle colors, OOO_VENDOR with Oracle Corp.,
  and the filename redhat.soc with oracle.soc in specfile bug#10911

[1:3.2.1-19.6.5]
- Related: rhbz#671087 set right file permissions

[1:3.2.1-19.6.4]
- Resolves: rhbz#671087 file locks are not created with gvfs-sftp
  volumes with OpenOffice.org

[1:3.2.1-19.6.3]
- Resolves: rhbz#642200 openoffice.org various flaws
- CVE-2010-4643 heap based buffer overflow when parsing TGA files

[1:3.2.1-19.6.2]
- Resolves: rhbz#642200 openoffice.org various flaws
- CVE-2010-4253 heap based buffer overflow in PPT import

[1:3.2.1-19.6.1]
- Resolves: rhbz#642200 openoffice.org various flaws
- CVE-2010-3450 directory traversal flaws in handling of XSLT jar filter
  descriptions and OXT extension files
- CVE-2010-3451 Array index error by insecure parsing of broken rtf
  tables
- CVE-2010-3452 Integer signedness error (crash) by processing certain
  RTF tags
- CVE-2010-3453 Heap-based buffer overflow by processing *.doc files
  with WW8 list styles with specially-crafted count of list levels
- CVE-2010-3454 Array index error by scanning document typography
  information of certain *.doc files
- CVE-2010-3689 soffice insecure LD_LIBRARY_PATH setting</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:47.394-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:39.795-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:39.353-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:10:51.080-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:10:51.080-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openoffice.org is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134209"/>
          <criterion comment="autocorr-af is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134302"/>
          <criterion comment="autocorr-bg is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134392"/>
          <criterion comment="autocorr-cs is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133492"/>
          <criterion comment="autocorr-da is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134306"/>
          <criterion comment="autocorr-de is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133792"/>
          <criterion comment="autocorr-en is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134078"/>
          <criterion comment="autocorr-es is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134434"/>
          <criterion comment="autocorr-eu is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133830"/>
          <criterion comment="autocorr-fa is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134408"/>
          <criterion comment="autocorr-fi is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134360"/>
          <criterion comment="autocorr-fr is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134225"/>
          <criterion comment="autocorr-ga is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134365"/>
          <criterion comment="autocorr-hu is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134474"/>
          <criterion comment="autocorr-it is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134333"/>
          <criterion comment="autocorr-ja is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133801"/>
          <criterion comment="autocorr-ko is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134344"/>
          <criterion comment="autocorr-lb is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133772"/>
          <criterion comment="autocorr-lt is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134436"/>
          <criterion comment="autocorr-mn is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134314"/>
          <criterion comment="autocorr-nl is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134422"/>
          <criterion comment="autocorr-pl is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134290"/>
          <criterion comment="autocorr-pt is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134435"/>
          <criterion comment="autocorr-ru is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133515"/>
          <criterion comment="autocorr-sk is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134511"/>
          <criterion comment="autocorr-sl is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134341"/>
          <criterion comment="autocorr-sv is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134490"/>
          <criterion comment="autocorr-tr is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134354"/>
          <criterion comment="autocorr-vi is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134465"/>
          <criterion comment="autocorr-zh is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134211"/>
          <criterion comment="broffice.org-base is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134509"/>
          <criterion comment="broffice.org-brand is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134352"/>
          <criterion comment="broffice.org-calc is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134270"/>
          <criterion comment="broffice.org-draw is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134472"/>
          <criterion comment="broffice.org-impress is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134495"/>
          <criterion comment="broffice.org-math is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134355"/>
          <criterion comment="broffice.org-writer is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134368"/>
          <criterion comment="openoffice.org-base is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134438"/>
          <criterion comment="openoffice.org-base-core is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134337"/>
          <criterion comment="openoffice.org-brand is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133957"/>
          <criterion comment="openoffice.org-bsh is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133518"/>
          <criterion comment="openoffice.org-calc is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134391"/>
          <criterion comment="openoffice.org-calc-core is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134383"/>
          <criterion comment="openoffice.org-core is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134347"/>
          <criterion comment="openoffice.org-devel is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134203"/>
          <criterion comment="openoffice.org-draw is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134517"/>
          <criterion comment="openoffice.org-draw-core is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134247"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134518"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134400"/>
          <criterion comment="openoffice.org-headless is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134057"/>
          <criterion comment="openoffice.org-impress is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134105"/>
          <criterion comment="openoffice.org-impress-core is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134507"/>
          <criterion comment="openoffice.org-javafilter is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134263"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134387"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134040"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133521"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134004"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134499"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134227"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134377"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134404"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134015"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134190"/>
          <criterion comment="openoffice.org-langpack-dz is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134197"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134286"/>
          <criterion comment="openoffice.org-langpack-en is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134448"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134444"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134157"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134443"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134195"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134476"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133688"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134505"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133523"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134513"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134296"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133625"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134356"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134568"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134158"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134618"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134578"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134601"/>
          <criterion comment="openoffice.org-langpack-mai_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134589"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134534"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134150"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134318"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134109"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134417"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134625"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134483"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134577"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134592"/>
          <criterion comment="openoffice.org-langpack-pa is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134586"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134542"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134178"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133629"/>
          <criterion comment="openoffice.org-langpack-ro is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134413"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134620"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134497"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134527"/>
          <criterion comment="openoffice.org-langpack-sr is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134427"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134630"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134475"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134308"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134363"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134406"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134050"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134186"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134609"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134579"/>
          <criterion comment="openoffice.org-langpack-uk is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134571"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134330"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134441"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134276"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134322"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134608"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134547"/>
          <criterion comment="openoffice.org-math is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134151"/>
          <criterion comment="openoffice.org-math-core is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134525"/>
          <criterion comment="openoffice.org-ogltrans is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134585"/>
          <criterion comment="openoffice.org-opensymbol-fonts is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134541"/>
          <criterion comment="openoffice.org-pdfimport is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134624"/>
          <criterion comment="openoffice.org-presentation-minimizer is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134498"/>
          <criterion comment="openoffice.org-presenter-screen is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134487"/>
          <criterion comment="openoffice.org-pyuno is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134402"/>
          <criterion comment="openoffice.org-report-builder is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134612"/>
          <criterion comment="openoffice.org-rhino is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134420"/>
          <criterion comment="openoffice.org-sdk is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134523"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134009"/>
          <criterion comment="openoffice.org-testtools is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134242"/>
          <criterion comment="openoffice.org-ure is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134410"/>
          <criterion comment="openoffice.org-wiki-publisher is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134439"/>
          <criterion comment="openoffice.org-writer is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134480"/>
          <criterion comment="openoffice.org-writer-core is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134508"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 0:3.2.1-19.6.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134124"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28206" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0195 -- php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0195.html" ref_id="ELSA-2011-0195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5016" ref_id="CVE-2009-5016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3709" ref_id="CVE-2010-3709"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3870" ref_id="CVE-2010-3870"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4645" ref_id="CVE-2010-4645"/>
        <description>[5.3.2-6.1]
- add security fixes for CVE-2010-3709, CVE-2010-3870,
  CVE-2009-5016, CVE-2010-4645 (#670461)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:51.413-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:39.377-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:38.982-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:24:47.096-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:24:47.096-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:133715"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134421"/>
          <criterion comment="php-cli is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134496"/>
          <criterion comment="php-common is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134524"/>
          <criterion comment="php-dba is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134591"/>
          <criterion comment="php-devel is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134566"/>
          <criterion comment="php-embedded is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134239"/>
          <criterion comment="php-enchant is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134463"/>
          <criterion comment="php-gd is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134280"/>
          <criterion comment="php-imap is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134301"/>
          <criterion comment="php-intl is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134096"/>
          <criterion comment="php-ldap is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134604"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134510"/>
          <criterion comment="php-mysql is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134519"/>
          <criterion comment="php-odbc is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134274"/>
          <criterion comment="php-pdo is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:133684"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134416"/>
          <criterion comment="php-process is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134149"/>
          <criterion comment="php-pspell is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134634"/>
          <criterion comment="php-recode is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134666"/>
          <criterion comment="php-snmp is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:133896"/>
          <criterion comment="php-soap is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134034"/>
          <criterion comment="php-tidy is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134326"/>
          <criterion comment="php-xml is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134662"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134643"/>
          <criterion comment="php-zts is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:133971"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28197" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0164 -- mysql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0164.html" ref_id="ELSA-2011-0164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3677" ref_id="CVE-2010-3677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3678" ref_id="CVE-2010-3678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3679" ref_id="CVE-2010-3679"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3680" ref_id="CVE-2010-3680"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3681" ref_id="CVE-2010-3681"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3682" ref_id="CVE-2010-3682"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3683" ref_id="CVE-2010-3683"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3833" ref_id="CVE-2010-3833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3835" ref_id="CVE-2010-3835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3836" ref_id="CVE-2010-3836"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3837" ref_id="CVE-2010-3837"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3838" ref_id="CVE-2010-3838"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3839" ref_id="CVE-2010-3839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3840" ref_id="CVE-2010-3840"/>
        <description>[5.1.52-1.1]
- Update to MySQL 5.1.52, for various fixes described at
  http://dev.mysql.com/doc/refman/5.1/en/news-5-1-52.html
  including numerous small security issues
Resolves: #652553
- Sync with current Fedora package; this includes:
- Duplicate COPYING and EXCEPTIONS-CLIENT in -libs and -embedded subpackages,
  to ensure they are available when any subset of mysql RPMs are installed,
  per revised packaging guidelines
- Allow init script's STARTTIMEOUT/STOPTIMEOUT to be overridden from sysconfig</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:44.323-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:38.086-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:38.344-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:57:31.064-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:57:31.064-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134028"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134231"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134271"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134394"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134143"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134121"/>
          <criterion comment="mysql-server is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134373"/>
          <criterion comment="mysql-test is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28189" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0308 -- mailman security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mailman</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0308.html" ref_id="ELSA-2011-0308"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3089" ref_id="CVE-2010-3089"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0707" ref_id="CVE-2011-0707"/>
        <description>[3:2.1.12-14.2]
- fix #677848 - fixed build problem without brew

[3:2.1.12-14.1]
- fix #677848 - fixed CVE-2010-3089 and CVE-2011-0707</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:50.661-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:37.581-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:38.084-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:20:16.350-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:20:16.350-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="mailman is earlier than 0:2.1.12-14.el6_0.2" test_ref="oval:org.mitre.oval:tst:134174"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28187" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0979 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0979.html" ref_id="ELSA-2010-0979"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3864" ref_id="CVE-2010-3864"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4180" ref_id="CVE-2010-4180"/>
        <description>[1.0.0-4.2]
- disable code for SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG - CVE-2010-3864
  (#649304)

[1.0.0-4.1]
- fix race in extension parsing code - CVE-2010-3864 (#649304)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:42.721-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:36.052-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:37.524-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:44:28.263-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:44:28.263-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:1.0.0-4.el6_0.2" test_ref="oval:org.mitre.oval:tst:134253"/>
          <criterion comment="openssl-devel is earlier than 0:1.0.0-4.el6_0.2" test_ref="oval:org.mitre.oval:tst:134293"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-4.el6_0.2" test_ref="oval:org.mitre.oval:tst:134269"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-4.el6_0.2" test_ref="oval:org.mitre.oval:tst:134334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28181" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0258 -- subversion security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0258.html" ref_id="ELSA-2011-0258"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3315" ref_id="CVE-2010-3315"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4539" ref_id="CVE-2010-4539"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4644" ref_id="CVE-2010-4644"/>
        <description>[1.6.11-2.2]
- add security fixes for CVE-2010-4644, CVE-2010-4539 (#672678)

[1.6.11-2.1]
- add security fix for CVE-2010-3315 (#640322)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:11.046-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:35.333-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:37.233-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:17:43.323-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:17:43.323-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="subversion is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:134214"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:134287"/>
          <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:134320"/>
          <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:133993"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:134291"/>
          <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:133886"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:134066"/>
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:134277"/>
          <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:134212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28178" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0283 -- kernel security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0283.html" ref_id="ELSA-2011-0283"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4165" ref_id="CVE-2010-4165"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4169" ref_id="CVE-2010-4169"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4243" ref_id="CVE-2010-4243"/>
        <description>[2.6.32-71.18.1.el6]
- [netdrv] ixgbe: make sure FCoE DDP user buffers are really released by the HW (Frantisek Hrbata) [674002 617193]
- [netdrv] ixgbe: invalidate FCoE DDP context when no error status is available (Frantisek Hrbata) [674002 617193]
- [netdrv] ixgbe: avoid doing FCoE DDP when adapter is DOWN or RESETTING (Frantisek Hrbata) [674002 617193]
- [fcoe] libfc: remove tgt_flags from fc_fcp_pkt struct (Mike Christie) [666797 633915]
- [fcoe] libfc: use rport timeout values for fcp recovery (Frantisek Hrbata) [666797 633915]
- [fcoe] libfc: incorrect scsi host byte codes returned to scsi-ml (Mike Christie) [666797 633915]
- [scsi] scsi_dh_alua: fix overflow in alua_rtpg port group id check (Mike Snitzer) [673978 670572]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:46.464-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:34.939-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.995-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:31:09.963-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:31:09.963-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:133992"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:133860"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:133277"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:133339"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:134292"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:133674"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:133905"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:134303"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28170" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1441 -- icedtea-web security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1441.html" ref_id="ELSA-2011-1441"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3377" ref_id="CVE-2011-3377"/>
        <description>[1.0.6-1]
- Updated to 1.0.6
- Resolves: rhbz#744738
- Resolves: rhbz#745414</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:29.648-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:34.627-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.785-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:29:18.161-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:29:18.161-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="icedtea-web is earlier than 0:1.0.6-1.el6_1" test_ref="oval:org.mitre.oval:tst:132925"/>
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.0.6-1.el6_1" test_ref="oval:org.mitre.oval:tst:133061"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28169" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1328 -- qt security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1328.html" ref_id="ELSA-2011-1328"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3193" ref_id="CVE-2011-3193"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3194" ref_id="CVE-2011-3194"/>
        <description>[4.6.2-20]
- Resolves: #rhbz737813
   fix multiple flaws in Qt
   CVE-2011-3193, CVE-2011-3194

[4.6.2-19]
- Resolves: rhbz#679759, missing executable bit in qt-examples binaries
- Resolves: rhbz#716694, move macros.qt4 to -devel
- Resolves: rhbz#680088, rpmdiff failure

[4.6.2-18]
- Resolves: rhbz#562132, Malayalam rakar is not getting reordered</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:21.701-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:34.506-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.702-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:44:16.275-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:44:16.275-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qt is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:132922"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:133060"/>
          <criterion comment="qt-demos is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:133022"/>
          <criterion comment="qt-devel is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:132139"/>
          <criterion comment="qt-doc is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:132140"/>
          <criterion comment="qt-examples is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:132998"/>
          <criterion comment="qt-mysql is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:132953"/>
          <criterion comment="qt-odbc is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:133059"/>
          <criterion comment="qt-postgresql is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:132312"/>
          <criterion comment="qt-sqlite is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:132775"/>
          <criterion comment="qt-x11 is earlier than 0:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:132971"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28168" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1507 -- libarchive security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libarchive</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1507.html" ref_id="ELSA-2011-1507"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1777" ref_id="CVE-2011-1777"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1778" ref_id="CVE-2011-1778"/>
        <description>[2.8.3-3]
- Security fixes (CVE-2011-1777, CVE-2011-1778) (#739939)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:26.583-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:34.269-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.586-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:48:44.223-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:48:44.223-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libarchive is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:132939"/>
          <criterion comment="libarchive-devel is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:133085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28166" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1465 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1465.html" ref_id="ELSA-2011-1465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1162" ref_id="CVE-2011-1162"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1577" ref_id="CVE-2011-1577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2494" ref_id="CVE-2011-2494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2699" ref_id="CVE-2011-2699"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2905" ref_id="CVE-2011-2905"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3188" ref_id="CVE-2011-3188"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3191" ref_id="CVE-2011-3191"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3353" ref_id="CVE-2011-3353"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3359" ref_id="CVE-2011-3359"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3363" ref_id="CVE-2011-3363"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3593" ref_id="CVE-2011-3593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4326" ref_id="CVE-2011-4326"/>
        <description>[2.6.32-131.21.1.el6]
- [net] ipv6/udp: fix the wrong headroom check (Thomas Graf) [753167 698170]

[2.6.32-131.20.1.el6]
- [net] vlan: fix panic when handling priority tagged frames (Andy Gospodarek) [742849 714936] {CVE-2011-3593}
- [netdrv] igb: fix WOL on second port of i350 device (Frantisek Hrbata) [743807 718293]
- [kernel] fix taskstats io infoleak (Jerome Marchand) [716847 716848] {CVE-2011-2494}
- [tpm] Zero buffer after copying to userspace (Jiri Benc) [732632 732633] {CVE-2011-1162}
- [scsi] Revert megaraid_sas: Driver only report tape drive, JBOD and logic drives (Tomas Henzl) [741167 736667]
- [x86] acpi: Prevent acpiphp from deadlocking on PCI-to-PCI bridge remove (Prarit Bhargava) [745557 732706]
- [net] sctp: deal with multiple COOKIE_ECHO chunks (Frantisek Hrbata) [743510 729220]
- [scsi] iscsi_tcp: fix locking around iscsi sk user data (Mike Christie) [741704 647268]
- [kernel] first time swap use results in heavy swapping (Hendrik Brueckner) [747868 722461]
- [scsi] Reduce error recovery time by reducing use of TURs (Mike Christie) [744811 691945]
- [fs] cifs: add fallback in is_path_accessible for old servers (Jeff Layton) [738301 692709] {CVE-2011-3363}
- [fs] cifs: always do is_path_accessible check in cifs_mount (Jeff Layton) [738301 692709] {CVE-2011-3363}
- [net] ipv6: fix NULL dereference in udp6_ufo_fragment() (Jason Wang) [748808 740465]
- [net] ipv6: make fragment identifications less predictable (Jiri Pirko) [723432 723433] {CVE-2011-2699}

[2.6.32-131.19.1.el6]
- [scsi] scan: don't fail scans when host is in recovery (Mike Christie) [734774 713682]
- [netdrv] b43: allocate receive buffers big enough for max frame len + offset (RuiRui Yang) [738204 738205] {CVE-2011-3359}
- [fs] fuse: check size of FUSE_NOTIFY_INVAL_ENTRY message (RuiRui Yang) [736764 736765] {CVE-2011-3353}
- [fs] cifs: fix possible memory corruption in CIFSFindNext (Jeff Layton) [737482 730354] {CVE-2011-3191}
- [kernel] perf tools: do not look at ./config for configuration (Jiri Benc) [730203 730204] {CVE-2011-2905}
- [x86] mm: Fix pgd_lock deadlock (Andrew Jones) [737570 691310]
- [mm] pdpte registers are not flushed when PGD entry is changed in x86 PAE mode (Andrew Jones) [737570 691310]
- [mm] Revert 'fix pgd_lock deadlock' (Andrew Jones) [737570 691310]
- [fs] corrupted GUID partition tables can cause kernel oops (Jerome Marchand) [695981 695982] {CVE-2011-1577}
- [net] Compute protocol sequence numbers and fragment IDs using MD5. (Jiri Pirko) [732664 732665] {CVE-2011-3188}
- [crypto] Move md5_transform to lib/md5.c (Jiri Pirko) [732664 732665] {CVE-2011-3188}
- [fs] SUNRPC: Fix use of static variable in rpcb_getport_async (Steve Dickson) [740230 723650]
- [fs] NFSv4.1: update nfs4_fattr_bitmap_maxsz (Steve Dickson) [740230 723650]
- [fs] SUNRPC: Fix a race between work-queue and rpc_killall_tasks (Steve Dickson) [740230 723650]
- [fs] SUNRPC: Ensure we always run the tk_callback before tk_action (Steve Dickson) [740230 723650]
- [misc] enclosure: fix error path to actually return ERR_PTR() on error (Tomas Henzl) [741166 713730]
- [virt] KVM: make guest mode entry to be rcu quiescent state (Gleb Natapov) [740352 712653]
- [virt] rcu: provide rcu_virt_note_context_switch() function (Gleb Natapov) [740352 712653]

[2.6.32-131.18.1.el6]
- [sched] wait_for_completion_interruptible_timeout() should return signed long (J. Bruce Fields) [745413 738379]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:07.981-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:33.957-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.425-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:34:41.529-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:34:41.529-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:133206"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:133230"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:132941"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:133069"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:133113"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:133102"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:132921"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:133072"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28165" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1422 -- openswan security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1422.html" ref_id="ELSA-2011-1422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4073" ref_id="CVE-2011-4073"/>
        <description>[2.6.32-4.4]
Resolves: #748969 CVE-2011-4073 updated patch by upstream

[2.6.32-4.3]
Resolves: #748969 CVE-2011-4073</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:13.029-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:33.779-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.319-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:15:47.384-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:15:47.384-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:133284"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:133360"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:133191"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:133254"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28161" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1815 -- icu security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>icu</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1815.html" ref_id="ELSA-2011-1815"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4599" ref_id="CVE-2011-4599"/>
        <description>[4.2.1-9.1]

- Resolves: rhbz#766539 CVE-2011-4599 localeID overflow</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:28.837-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:33.464-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:36.110-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:57:17.000-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:57:17.000-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="icu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:132863"/>
            <criterion comment="libicu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:133134"/>
            <criterion comment="libicu-devel is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:133051"/>
            <criterion comment="libicu-doc is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:133137"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="icu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:133053"/>
            <criterion comment="libicu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:132537"/>
            <criterion comment="libicu-devel is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:132828"/>
            <criterion comment="libicu-doc is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:132916"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28159" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1110 -- foomatic security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>foomatic</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1110.html" ref_id="ELSA-2011-1110"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2964" ref_id="CVE-2011-2964"/>
        <description>[4.0.4-1:.1]
- Applied patch to fix improper sanitization of command line options
  (CVE-2011-2697, bug #721001).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:28.116-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:33.126-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.931-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:43:36.355-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:43:36.355-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="foomatic is earlier than 0:4.0.4-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133556"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28158" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2029 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2029.html" ref_id="ELSA-2011-2029"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1833" ref_id="CVE-2011-1833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2484" ref_id="CVE-2011-2484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2496" ref_id="CVE-2011-2496"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2723" ref_id="CVE-2011-2723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2898" ref_id="CVE-2011-2898"/>
        <description>[2.6.32-200.20.1.el6uek] - af_packet: prevent information leak {CVE-2011-2898}
          - gro: Only reset frag0 when skb can be pulled {CVE-2011-2723} - vm: fix vm_pgoff wrap in
          stack expansion {CVE-2011-2496} - vm: fix vm_pgoff wrap in upward expansion
          {CVE-2011-2496} - taskstats: don't allow duplicate entries in listener mode
          {CVE-2011-2484} - Ecryptfs: Add mount option to check uid of device being mounted
          {CVE-2011-1833}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:12.632-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:32.953-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.780-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36772 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:55.892-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:49.522-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133125"/>
            <criterion comment="ofa-2.6.32-200.20.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132745"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133435"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133031"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133104"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133436"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133407"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.20.1.el5uek" test_ref="oval:org.mitre.oval:tst:133393"/>
            <criterion comment="ofa-2.6.32-200.20.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:133046"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133428"/>
            <criterion comment="ofa-2.6.32-200.20.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132726"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133233"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133016"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133392"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:132879"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133184"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.20.1.el6uek" test_ref="oval:org.mitre.oval:tst:133229"/>
            <criterion comment="ofa-2.6.32-200.20.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133317"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28157" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2025 -- Unbreakable Enterprise kernel security and bug fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2025.html" ref_id="ELSA-2011-2025"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1576" ref_id="CVE-2011-1576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1898" ref_id="CVE-2011-1898"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2183" ref_id="CVE-2011-2183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2491" ref_id="CVE-2011-2491"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2492" ref_id="CVE-2011-2492"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2495" ref_id="CVE-2011-2495"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2497" ref_id="CVE-2011-2497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2517" ref_id="CVE-2011-2517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2695" ref_id="CVE-2011-2695"/>
        <description>[2.6.32-200.19.1.el6uek] - Apply new fix for CVE-2011-1576.
          [2.6.32-200.18.1.el6uek] - Revert 'proc: fix a race in do_io_accounting'
          [2.6.32-200.17.1.el6uek] - net: Fix memory leak/corruption on VLAN GRO_DROP
          {CVE-2011-1576} - iommu-api: Extension to check for interrupt remapping {CVE-2011-1898} -
          KVM: IOMMU: Disable device assignment without interrupt remapping {CVE-2011-1898} - ext4:
          Fix max file size and logical block counting of extent format file {CVE-2011-2695} -
          nl80211: fix overflow in ssid_len {CVE-2011-2517} - Bluetooth: Prevent buffer overflow in
          l2cap config request {CVE-2011-2497} - proc: fix a race in do_io_accounting()
          {CVE-2011-2495} - proc: restrict access to /proc/PID/io {CVE-2011-2495} - Bluetooth: l2cap
          and rfcomm: fix 1 byte infoleak to userspace {CVE-2011-2492} - NLM: Don't hang forever on
          NLM unlock requests {CVE-2011-2491} - ksm: fix NULL pointer dereference in
          scan_get_next_rmap_item() {CVE-2011-2183}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:36.061-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:32.774-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.556-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:133312 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:52.084-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:48.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133383"/>
            <criterion comment="ofa-2.6.32-200.19.1.el5uek is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133565"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133267"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133551"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133597"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:132786"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133475"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.19.1.el5uek" test_ref="oval:org.mitre.oval:tst:133446"/>
            <criterion comment="ofa-2.6.32-200.19.1.el5uekdebug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133440"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:132623"/>
            <criterion comment="ofa-2.6.32-200.19.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133312"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133536"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133589"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133618"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133324"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133609"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.19.1.el6uek" test_ref="oval:org.mitre.oval:tst:133421"/>
            <criterion comment="ofa-2.6.32-200.19.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28156" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0256 -- dhcp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0256.html" ref_id="ELSA-2011-0256"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0413" ref_id="CVE-2011-0413"/>
        <description>[12:4.1.1-12.P1.2]
- CVE-2011-0413: Unexpected abort caused by a DHCPv6 decline message (#672994)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:54.675-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:32.538-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.437-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:02:29.909-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:02:29.909-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dhcp is earlier than 0:4.1.1-12.P1.el6_0.2" test_ref="oval:org.mitre.oval:tst:134102"/>
          <criterion comment="dhclient is earlier than 0:4.1.1-12.P1.el6_0.2" test_ref="oval:org.mitre.oval:tst:134222"/>
          <criterion comment="dhcp-devel is earlier than 0:4.1.1-12.P1.el6_0.2" test_ref="oval:org.mitre.oval:tst:133942"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28153" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1791 -- squid security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1791.html" ref_id="ELSA-2011-1791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4096" ref_id="CVE-2011-4096"/>
        <description>[-7:3.1.10-1.el6_2.1]
- Resolves: #755016 - CVE-2011-4096: Invalid free by processing CNAME DNS record</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:29.136-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:32.358-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.320-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:45:44.615-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:45:44.615-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="squid is earlier than 0:3.1.10-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:133023"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28147" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0356 -- krb5 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0356.html" ref_id="ELSA-2011-0356"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0284" ref_id="CVE-2011-0284"/>
        <description>[1.8.2-3.6]
- add revised upstream patch to fix double-free in KDC while returning
  typed-data with errors (CVE-2011-0284, #681564)

[1.8.2-3.5]
- add upstream patches to fix double-free in KDC while returning typed-data
  with errors (CVE-2011-0284, #681564)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:05.827-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:31.735-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:35.036-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:40:32.960-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:40:32.960-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:133612"/>
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:134173"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:133841"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:133610"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:134148"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:134188"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:133965"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28146" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0791 -- tomcat6 security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0791.html" ref_id="ELSA-2011-0791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3718" ref_id="CVE-2010-3718"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4172" ref_id="CVE-2010-4172"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0013" ref_id="CVE-2011-0013"/>
        <description>[6.0.24-33]
- resolves: rhbz 695284 - multiple instances logging fiasco

[6.0.24-32]
- Resolves: rhbz 698624 - inet4address can't be cast to String

[6.0.24-31]
- Resolves: rhbz 656403 - cve-2010-4172 jsp syntax error

[6.0.24-30]
- Resolves: rhbz#697504 initscript logging location

[6.0.24-29]
- Resolves: rhbz#656403, rhbz#675926, rhbz#676011
- CVE-2010-4172, CVE-2010-3718, CVE-2011-0013, CVE-2010-4476,
- CVE-2011-0534

[6.0.24-28]
- Resovles  rhbz#695284 - wrapper logs to different locations
- CVE-2010-4172, CVE-2011-0013, CVE-2010-3718 commented out 
- until needed.

[6.0.24-27]
- naming-factory-dbcp missing fix in tomcat6.conf
- Add Obsoletes for log4j

[6.0.24-26]
- Add log4j to package lib. Corrected typo in log4 Provides
- epock versus epoch

[6.0.24-25]
- Installed permissions do not allow tomcat to start
- incrementing NVR so yum won't get confused with the zstream</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:43.017-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:31.386-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:34.925-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:54:28.084-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:54:28.084-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:133858"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:133824"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:133768"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:133080"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:133405"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:133355"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:133856"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:133550"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:133809"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28145" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0953 -- system-config-firewall security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>system-config-firewall</product>
          <product>system-config-printer</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0953.html" ref_id="ELSA-2011-0953"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2520" ref_id="CVE-2011-2520"/>
        <description>system-config-firewall:

[1.2.27-3.3]
- fixed possible privilege escalation flaw via use of python pickle
  (CVE-2011-2520), replaced pickle by json (rhbz#717985)
- stop D-BUS firewall mechanism on update

system-config-printer:

[1.1.16-17:.2]
- Build pycups with -fno-strict-aliasing compiler option to avoid
  compiler warnings.

[1.1.16-17:.1]
- Adapted to system-config-firewall API change (bug #717985, CVE-2011-2520).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:31.205-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:31.114-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:34.807-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:41:51.178-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:41:51.178-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="system-config-firewall is earlier than 0:1.2.27-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133631"/>
          <criterion comment="system-config-printer is earlier than 0:1.1.16-17.el6_1.2" test_ref="oval:org.mitre.oval:tst:133364"/>
          <criterion comment="system-config-firewall-base is earlier than 0:1.2.27-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133593"/>
          <criterion comment="system-config-firewall-tui is earlier than 0:1.2.27-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133454"/>
          <criterion comment="system-config-printer-libs is earlier than 0:1.1.16-17.el6_1.2" test_ref="oval:org.mitre.oval:tst:133514"/>
          <criterion comment="system-config-printer-udev is earlier than 0:1.1.16-17.el6_1.2" test_ref="oval:org.mitre.oval:tst:133693"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28144" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0862 -- subversion security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0862.html" ref_id="ELSA-2011-0862"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1752" ref_id="CVE-2011-1752"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1783" ref_id="CVE-2011-1783"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1921" ref_id="CVE-2011-1921"/>
        <description>[1.6.11-2.4]
- add security fixes for CVE-2011-1752, CVE-2011-1783, CVE-2011-1921 (#709220)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:44.555-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:30.583-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:34.638-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:49:57.899-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:49:57.899-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133133"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133761"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:132934"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133798"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133602"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:133663"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133427"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133108"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133606"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133147"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133725"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133807"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133765"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133691"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:133642"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28135" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0930 -- NetworkManager security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>NetworkManager</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0930.html" ref_id="ELSA-2011-0930"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2176" ref_id="CVE-2011-2176"/>
        <description>[0.8.1-9_el6_1.1]
- core: CVE-2011-2176: check for authorization when activating shared wifi connections (rh #705806)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:21.744-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:28.942-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.944-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:02:34.138-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:02:34.138-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="NetworkManager is earlier than 0:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:133508"/>
          <criterion comment="NetworkManager-devel is earlier than 0:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:133160"/>
          <criterion comment="NetworkManager-glib is earlier than 0:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:133377"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 0:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:133495"/>
          <criterion comment="NetworkManager-gnome is earlier than 0:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:133331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28132" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1132 -- dbus security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1132.html" ref_id="ELSA-2011-1132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2200" ref_id="CVE-2011-2200"/>
        <description>[1:1.2.24-5]
- Merge changes from RHEL-6 branch:
  * Drop default patch fuzz
  * Merge CVE-2010-4352.patch from RHEL-6_0-Z
- Apply patches for CVE-2011-2200
- Resolves: #725313</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:37.338-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:28.465-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.724-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:30:13.244-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:30:13.244-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:133462"/>
            <criterion comment="dbus-devel is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:133240"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:133299"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:133433"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:133587"/>
            <criterion comment="dbus-devel is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:132630"/>
            <criterion comment="dbus-doc is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:133123"/>
            <criterion comment="dbus-libs is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:133045"/>
            <criterion comment="dbus-x11 is earlier than 0:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:133574"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28131" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0891 -- pam security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pam</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0891.html" ref_id="ELSA-2010-0891"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3316" ref_id="CVE-2010-3316"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3435" ref_id="CVE-2010-3435"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3853" ref_id="CVE-2010-3853"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4707" ref_id="CVE-2010-4707"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4708" ref_id="CVE-2010-4708"/>
        <description>[1.1.1-4.1]
- fix insecure dropping of priviledges in pam_xauth, pam_env,
  and pam_mail - CVE-2010-3316 (#637898), CVE-2010-3435 (#641335)
- fix insecure executing of scripts with user supplied environment
  variables in pam_namespace - CVE-2010-3853 (#643043)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:53.060-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:28.240-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.608-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:02:42.637-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:02:42.637-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pam is earlier than 0:1.1.1-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:134561"/>
          <criterion comment="pam-devel is earlier than 0:1.1.1-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:134442"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28130" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1439 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1439.html" ref_id="ELSA-2011-1439"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3647" ref_id="CVE-2011-3647"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3648" ref_id="CVE-2011-3648"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3650" ref_id="CVE-2011-3650"/>
        <description>[3.1.16-2.0.1.el6_1]
- Replaced thunderbird-redhat-default-prefs.js with
  thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[3.1.16-2]
- Update to 3.1.16</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:14.099-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:27.842-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.430-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:54:01.449-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:54:01.449-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:3.1.16-2.0.1.el6_1" test_ref="oval:org.mitre.oval:tst:132926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28127" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1154 -- libXfont security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1154.html" ref_id="ELSA-2011-1154"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2895" ref_id="CVE-2011-2895"/>
        <description>[1.4.1-2]
- cve-2011-2895.patch: LZW decompression heap corruption</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:43.948-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:27.661-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.312-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:58:01.416-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:58:01.416-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:133367"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:133247"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:133493"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:133416"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28125" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1423 -- php53 and php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1423.html" ref_id="ELSA-2011-1423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0708" ref_id="CVE-2011-0708"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1148" ref_id="CVE-2011-1148"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1466" ref_id="CVE-2011-1466"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1468" ref_id="CVE-2011-1468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1469" ref_id="CVE-2011-1469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1471" ref_id="CVE-2011-1471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1938" ref_id="CVE-2011-1938"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2202" ref_id="CVE-2011-2202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2483" ref_id="CVE-2011-2483"/>
        <description>[5.3.3-3.3]
- improve CVE-2011-1466 fix to cover CAL_GREGORIAN, CAL_JEWISH

[5.3.3-3.1]
- add security fixes for CVE-2011-2483, CVE-2011-0708, CVE-2011-1148,
  CVE-2011-1466, CVE-2011-1468, CVE-2011-1469, CVE-2011-1470,
  CVE-2011-1471, CVE-2011-1938, and CVE-2011-2202 (#740731)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:09.898-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:26.939-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:33.014-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:50:08.418-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:50:08.418-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133213"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133369"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133178"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133194"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133351"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133210"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:132902"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133290"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133244"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133009"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133294"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133138"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:132484"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133329"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133234"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133242"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133309"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133198"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:132607"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:133168"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:132577"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133280"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133297"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133216"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133328"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133321"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133223"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133082"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133218"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132871"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133231"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133096"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133119"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132393"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133348"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132933"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133307"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133161"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133122"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133005"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133327"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133159"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133298"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132796"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133135"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:133002"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:132957"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28122" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1391 -- httpd security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1391.html" ref_id="ELSA-2011-1391"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3348" ref_id="CVE-2011-3348"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3368" ref_id="CVE-2011-3368"/>
        <description>[2.2.15-9.0.1.el6_1.3]
- replace index.html with Oracle's index page
- update vstring in specfile

[2.2.15-9.3]
- add security fixes for CVE-2011-3347, CVE-2011-3368 (#743901)
- fix regressions in CVE-2011-3192 patch (#736592)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:11.726-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:26.282-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:32.687-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:47:25.292-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:47:25.292-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="httpd is earlier than 0:2.2.15-9.0.1.el6_1.3" test_ref="oval:org.mitre.oval:tst:132728"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.15-9.0.1.el6_1.3" test_ref="oval:org.mitre.oval:tst:133252"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.15-9.0.1.el6_1.3" test_ref="oval:org.mitre.oval:tst:132829"/>
          <criterion comment="httpd-tools is earlier than 0:2.2.15-9.0.1.el6_1.3" test_ref="oval:org.mitre.oval:tst:133304"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.15-9.0.1.el6_1.3" test_ref="oval:org.mitre.oval:tst:133343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28119" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1102 -- libsoup security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libsoup</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1102.html" ref_id="ELSA-2011-1102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2524" ref_id="CVE-2011-2524"/>
        <description>[2.28.2-1.1]
- Patch for CVE-2011-2524</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:33">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:31.683-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:24.952-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:32.107-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:50:37.374-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:50:37.374-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libsoup is earlier than 0:2.28.2-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133567"/>
          <criterion comment="libsoup-devel is earlier than 0:2.28.2-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28114" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1807 -- jasper security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>jasper</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1807.html" ref_id="ELSA-2011-1807"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4516" ref_id="CVE-2011-4516"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4517" ref_id="CVE-2011-4517"/>
        <description>[1.900.1-15.1]
- CERT VU#887409: heap buffer overflow flaws lead to arbitrary code execution
  (#749149)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:25.123-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:23.579-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:31.418-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:33:01.644-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:33:01.644-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="jasper is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:133068"/>
          <criterion comment="jasper-devel is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:132951"/>
          <criterion comment="jasper-libs is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:132972"/>
          <criterion comment="jasper-utils is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:133081"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28112" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1919 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1919.html" ref_id="ELSA-2014-1919"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1587" ref_id="CVE-2014-1587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1590" ref_id="CVE-2014-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1592" ref_id="CVE-2014-1592"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1593" ref_id="CVE-2014-1593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1594" ref_id="CVE-2014-1594"/>
        <description>[31.3.0-4.0.1]
- Add firefox-oracle-default-prefs.js and firefox-oracle-default-bookmarks.html
  and remove the corresponding Red Hat ones

[31.3.0-4]
- Update to 31.3.0 ESR Build 2
- Fix for geolocation API (rhbz#1063739)

[31.2.0-5]
- splice workaround (rhbz#1150082)

[31.2.0-4]
- ppc build fix (rhbz#1151959)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:28.953-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:22.281-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:25.022-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:31.3.0-4.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:135924"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:31.3.0-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135776"/>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criterion comment="firefox is earlier than 0:31.3.0-3.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135255"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28111" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1221 -- samba and cifs-utils security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cifs-utils</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1221.html" ref_id="ELSA-2011-1221"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1678" ref_id="CVE-2011-1678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2522" ref_id="CVE-2011-2522"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2694" ref_id="CVE-2011-2694"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2724" ref_id="CVE-2011-2724"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3585" ref_id="CVE-2011-3585"/>
        <description>cifs-utils:

[4.8.1-2.2]
- fix handling of check_newline return code in mount.cifs (bz 725508)

[4.8.1-2.1]
- mount.cifs: handle ENOSPC/EFBIG condition when altering mtab (bz 725508)

samba:

[3.5.6-86.4]
- Fix cleartext authentication after applying Windows security patch KB2536276
- resolves: #728517

[3.5.6-86.3]
- Security Release, fixes CVE-2011-2694, CVE-2011-2522
- resolves: #722560

[3.5.6-86.2]
- Fix cups location publishing
- resolves: #716374

[3.5.6-86.1]
- Fix joining principal
- resolves: #717563</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:22.681-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:23.248-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:31.213-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:44:30.142-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:44:30.142-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cifs-utils is earlier than 0:4.8.1-2.el6_1.2" test_ref="oval:org.mitre.oval:tst:133150"/>
          <criterion comment="samba is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133595"/>
          <criterion comment="libsmbclient is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133594"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133121"/>
          <criterion comment="samba-client is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133477"/>
          <criterion comment="samba-common is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133391"/>
          <criterion comment="samba-doc is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133581"/>
          <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:132860"/>
          <criterion comment="samba-swat is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133553"/>
          <criterion comment="samba-winbind is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133570"/>
          <criterion comment="samba-winbind-clients is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133165"/>
          <criterion comment="samba-winbind-devel is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133336"/>
          <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:133207"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28110" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0335 -- tomcat6 security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0335.html" ref_id="ELSA-2011-0335"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4476" ref_id="CVE-2010-4476"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0534" ref_id="CVE-2011-0534"/>
        <description>[0:6.0.24-24]
- Resolves: rhbz#674601
- Removed wildcard in main %files that caused duplicate ownership
- of log4j.properties

[0:6.0.24-23]
- Resolves: rhbz#674601
- Reverse - tomcat user requires login shell
- Reverse - rhbz 611244 tomcat-juli missing symlink
- PM/QE decision to include only the security fixes. The rhbzs
- will be taken care of during the rebase to 6.0.33.
- Did not Reverse - rhbz 676922 - additionally instancs of tomcat are broken
- Too many users depend upon it.

[0:6.0.24-22]
- Resolves - tomcat user requires login shell

[0:6.0.24-21]
- Resolves: 676922 - additionally created instances of tomcat
- are broken

[0:6.0.24-20]
- Resolves: rbz# 676922
- Resolves: init script LSB compliance
- Resolves: multiple instances of tomcat.
- Resolves: tomcat-juli missing symlink

[0:6.0.24-18]
- Resolves directory permission problems

[0:6.0.24-17]
- Resolves: CVE-2011-0534 rhbz#674601

[0:6.0.24-16]
- Resolves rhbz#674601 JDK Double.parseDouble DoS</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:48.887-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:23.056-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:31.100-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:01:51.135-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:01:51.135-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:134213"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:133912"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:134133"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:134026"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:133901"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:134083"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:133847"/>
          <criterion comment="tomcat6-log4j is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:134073"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:133248"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:133677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28108" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0423 -- postfix security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>postfix</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0423.html" ref_id="ELSA-2011-0423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0411" ref_id="CVE-2011-0411"/>
        <description>[2:2.6.6-2.1]
- fix CVE-2011-0411 (#682978)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:51.968-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:22.875-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:31.012-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:37:02.744-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:37:02.744-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="postfix is earlier than 0:2.6.6-2.1.el6_0" test_ref="oval:org.mitre.oval:tst:134137"/>
          <criterion comment="postfix-perl-scripts is earlier than 0:2.6.6-2.1.el6_0" test_ref="oval:org.mitre.oval:tst:133819"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28105" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0376 -- dbus security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0376.html" ref_id="ELSA-2011-0376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4352" ref_id="CVE-2010-4352"/>
        <description>[1:1.2.24-4]
- Apply patch for CVE-2010-4352
- Resolves: #684852</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:05.118-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:22.509-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:30.808-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:51:42.856-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:51:42.856-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:134112"/>
            <criterion comment="dbus-devel is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:134116"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:133226"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:133522"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:134206"/>
            <criterion comment="dbus-devel is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:134193"/>
            <criterion comment="dbus-doc is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:133828"/>
            <criterion comment="dbus-libs is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:133813"/>
            <criterion comment="dbus-x11 is earlier than 0:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:133703"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28104" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1380 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1380.html" ref_id="ELSA-2011-1380"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3389" ref_id="CVE-2011-3389"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3521" ref_id="CVE-2011-3521"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544" ref_id="CVE-2011-3544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3547" ref_id="CVE-2011-3547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3548" ref_id="CVE-2011-3548"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3551" ref_id="CVE-2011-3551"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3552" ref_id="CVE-2011-3552"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3553" ref_id="CVE-2011-3553"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3554" ref_id="CVE-2011-3554"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3556" ref_id="CVE-2011-3556"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3557" ref_id="CVE-2011-3557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3558" ref_id="CVE-2011-3558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3560" ref_id="CVE-2011-3560"/>
        <description>[1:1.6.0.0-1.40.1.9.10]
- Resolves: rhbz#744788
- Bumped to IcedTea6 1.9.8
-removed font copying
 Security fixes
  - S7000600, CVE-2011-3547: InputStream skip() information leak
  - S7019773, CVE-2011-3548: mutable static AWTKeyStroke.ctor
  - S7023640, CVE-2011-3551: Java2D TransformHelper integer overflow
  - S7032417, CVE-2011-3552: excessive default UDP socket limit under SecurityManager
  - S7046823, CVE-2011-3544: missing SecurityManager checks in scripting engine
  - S7055902, CVE-2011-3521: IIOP deserialization code execution
  - S7057857, CVE-2011-3554: insufficient pack200 JAR files uncompress error checks
  - S7064341, CVE-2011-3389: JSSE
  - S7070134, CVE-2011-3558: Hotspot unspecified issue
  - S7077466, CVE-2011-3556: RMI DGC server remote code execution
  - S7083012, CVE-2011-3557: RMI registry privileged code execution
  - S7096936, CVE-2011-3560: missing checkSetFactory calls in HttpsURLConnection
 NetX
  - PR794: javaws does not work if a Web Start app jar has a Class-Path element in the manifest</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:14.476-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:21.395-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:30.360-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:53:00.007-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:53:00.007-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:133283"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:133353"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:133088"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:133275"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.23.1.9.10.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:132798"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:132749"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:133302"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:133358"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:133387"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:133084"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28102" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0871 -- tigervnc security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tigervnc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0871.html" ref_id="ELSA-2011-0871"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1775" ref_id="CVE-2011-1775"/>
        <description>[1.0.90-0.15.20110314svn4359.1]
- viewer can send password without proper validation of X.509 certs
  (CVE-2011-1775)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:22.982-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:21.079-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:30.117-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:46:33.453-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:46:33.453-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tigervnc is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:133432"/>
          <criterion comment="tigervnc-server is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:132790"/>
          <criterion comment="tigervnc-server-applet is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:133640"/>
          <criterion comment="tigervnc-server-module is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:133608"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28100" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0452 -- libtiff security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0452.html" ref_id="ELSA-2011-0452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5022" ref_id="CVE-2009-5022"/>
        <description>[3.9.4-1.el6_0.3]
- Add fix for CVE-2009-5022
Resolves: #696143</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:45.165-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:20.891-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:30.014-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:49:41.220-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:49:41.220-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libtiff is earlier than 0:3.9.4-1.el6_0.3" test_ref="oval:org.mitre.oval:tst:133931"/>
          <criterion comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.3" test_ref="oval:org.mitre.oval:tst:133920"/>
          <criterion comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.3" test_ref="oval:org.mitre.oval:tst:133646"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28098" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1100 -- icedtea-web security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1100.html" ref_id="ELSA-2011-1100"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2513" ref_id="CVE-2011-2513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2514" ref_id="CVE-2011-2514"/>
        <description>[1.0.4-2]
- Added patch to make plugin table size mismatch a warning instead of error

[1.0.4-1]
- Bump to 1.0.4
- Resolves rhbz#718180</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:34.610-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:20.554-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:29.837-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:05:12.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:05:12.894-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="icedtea-web is earlier than 0:1.0.4-2.el6_1" test_ref="oval:org.mitre.oval:tst:133607"/>
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.0.4-2.el6_1" test_ref="oval:org.mitre.oval:tst:133730"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28095" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0858 -- bzip2 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bzip2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0858.html" ref_id="ELSA-2010-0858"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0405" ref_id="CVE-2010-0405"/>
        <description>[1.0.5-7]
- Resolves: #632268
  integer overflow flaw in BZ2_decompress - CVE-2010-0405
  (upstream patch)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:53.476-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:20.076-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:29.583-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:38:44.110-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:38:44.110-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bzip2 is earlier than 0:1.0.5-7.el6_0" test_ref="oval:org.mitre.oval:tst:134063"/>
          <criterion comment="bzip2-devel is earlier than 0:1.0.5-7.el6_0" test_ref="oval:org.mitre.oval:tst:134460"/>
          <criterion comment="bzip2-libs is earlier than 0:1.0.5-7.el6_0" test_ref="oval:org.mitre.oval:tst:134445"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28092" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2033 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2033.html" ref_id="ELSA-2011-2033"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1162" ref_id="CVE-2011-1162"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1577" ref_id="CVE-2011-1577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2494" ref_id="CVE-2011-2494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2699" ref_id="CVE-2011-2699"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3188" ref_id="CVE-2011-3188"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3191" ref_id="CVE-2011-3191"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3353" ref_id="CVE-2011-3353"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3593" ref_id="CVE-2011-3593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4326" ref_id="CVE-2011-4326"/>
        <description>[2.6.32-200.23.1.el6uek] - net: Remove atmclip.h to prevent break kabi check. -
          KConfig: add CONFIG_UEK5=n to ol6/config-generic [2.6.32-200.22.1.el6uek] - ipv6: make
          fragment identifications less predictable (Joe Jin) {CVE-2011-2699} - vlan: fix panic when
          handling priority tagged frames (Joe Jin) {CVE-2011-3593} - ipv6: udp: fix the wrong
          headroom check (Maxim Uvarov) {CVE-2011-4326} - b43: allocate receive buffers big enough
          for max frame len + offset (Maxim Uvarov) {CVE-2011-3359} - fuse: check size of
          FUSE_NOTIFY_INVAL_ENTRY message (Maxim Uvarov) {CVE-2011-3353} - cifs: fix possible memory
          corruption in CIFSFindNext (Maxim Uvarov) {CVE-2011-3191} - crypto: md5 - Add export
          support (Maxim Uvarov) {CVE-2011-2699} - fs/partitions/efi.c: corrupted GUID partition
          tables can cause kernel oops (Maxim Uvarov) {CVE-2011-1577} - block: use struct
          parsed_partitions *state universally in partition check code (Maxim Uvarov) - net: Compute
          protocol sequence numbers and fragment IDs using MD5. (Maxim Uvarov) {CVE-2011-3188} -
          crypto: Move md5_transform to lib/md5.c (Maxim Uvarov) {CVE-2011-3188} - perf tools: do
          not look at ./config for configuration (Maxim Uvarov) {CVE-2011-2905} - Make TASKSTATS
          require root access (Maxim Uvarov) {CVE-2011-2494} - TPM: Zero buffer after copying to
          userspace (Maxim Uvarov) {CVE-2011-1162} - TPM: Call tpm_transmit with correct size (Maxim
          Uvarov){CVE-2011-1161} - fnic: fix panic while booting in fnic(Xiaowei Hu) - Revert 'PCI
          hotplug: acpiphp: set current_state to D0 in register_slot' (Guru Anbalagane) - xen: drop
          xen_sched_clock in favour of using plain wallclock time (Jeremy Fitzhardinge)
          [2.6.32-200.21.1.el6uek] - PCI: Set device power state to PCI_D0 for device without native
          PM support (Ajaykumar Hotchandani) [orabug 13033435]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:32.900-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:19.313-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:29.204-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36842 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:54.713-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:45.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:132841"/>
            <criterion comment="ofa-2.6.32-200.23.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:133017"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:132801"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:132955"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:132705"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:133145"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:133048"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:133025"/>
            <criterion comment="ofa-2.6.32-200.23.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132799"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:133232"/>
            <criterion comment="ofa-2.6.32-200.23.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132844"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:132931"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:132839"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:133043"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:133067"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:132984"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:133182"/>
            <criterion comment="ofa-2.6.32-200.23.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28085" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0920 -- krb5-appl security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5-appl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0920.html" ref_id="ELSA-2011-0920"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1526" ref_id="CVE-2011-1526"/>
        <description>[1.0.1-2.1]
- ftpd: add candidate patch to detect setegid/setregid/setresgid and check
  for errors when calling them (MITKRB5-SA-2011-005, CVE-2011-1526, #713341)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:20.759-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:18.823-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.868-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:44:43.852-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:44:43.852-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5-appl is earlier than 0:1.0.1-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:133773"/>
          <criterion comment="krb5-appl-clients is earlier than 0:1.0.1-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:133617"/>
          <criterion comment="krb5-appl-servers is earlier than 0:1.0.1-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:133678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28082" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0329 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0329.html" ref_id="ELSA-2011-0329"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0714" ref_id="CVE-2011-0714"/>
        <description>[2.6.32-71.18.2.el6]
- [fs] sunrpc: Correct a misapplied patch (J. Bruce Fields) [678094 678146]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:58.428-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:18.652-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.757-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:47:39.736-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:47:39.736-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:133908"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:133702"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:133923"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:134135"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:134044"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:134081"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:134033"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:134159"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28081" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0545 -- squid security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0545.html" ref_id="ELSA-2011-0545"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3072" ref_id="CVE-2010-3072"/>
        <description>[3.1.10-1]
- Resolves: #639365 - Rebase squid to version 3.1.10
- Resolves: #666533 - small memleak in squid-3.1.4</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:54.118-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:18.454-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.673-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:57:01.530-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:57:01.530-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="squid is earlier than 0:3.1.10-1.el6" test_ref="oval:org.mitre.oval:tst:134029"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28078" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1458 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1458.html" ref_id="ELSA-2011-1458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4313" ref_id="CVE-2011-4313"/>
        <description>[32:9.7.3-2.3.P3]
- fix DOS against recursive servers (#754398)

[32:9.7.3-2.2.P3]
- update to 9.7.3-P3 (CVE-2011-2464)

[32:9.7.3-2.1.P1]
- update to 9.7.3-P1 (CVE-2011-1910)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:31.523-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:18.317-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.588-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:29:04.238-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:29:04.238-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132293"/>
            <criterion comment="bind-chroot is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133291"/>
            <criterion comment="bind-devel is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133018"/>
            <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:132539"/>
            <criterion comment="bind-libs is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133282"/>
            <criterion comment="bind-sdb is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133070"/>
            <criterion comment="bind-utils is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133086"/>
            <criterion comment="caching-nameserver is earlier than 0:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:133236"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:133047"/>
            <criterion comment="bind-chroot is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:132897"/>
            <criterion comment="bind-devel is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:132964"/>
            <criterion comment="bind-libs is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:133063"/>
            <criterion comment="bind-sdb is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:132873"/>
            <criterion comment="bind-utils is earlier than 0:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:132320"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28075" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1409 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1409.html" ref_id="ELSA-2011-1409"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3207" ref_id="CVE-2011-3207"/>
        <description>[1.0.0-10.5]
- initialize the X509_STORE_CTX properly for CRL lookups - CVE-2011-3207
  (#736087)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:07.585-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:17.969-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.369-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:08:48.246-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:08:48.246-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:132627"/>
          <criterion comment="openssl-devel is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:133335"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:132985"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:133313"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28071" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0347 -- openldap security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0347.html" ref_id="ELSA-2011-0347"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1024" ref_id="CVE-2011-1024"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1025" ref_id="CVE-2011-1025"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1081" ref_id="CVE-2011-1081"/>
        <description>[2.4.19-15.2]
- fix: security - DoS when submitting special MODRDN request (#680975)

[2.4.19-15.1]
- fix: CVE-2011-1024 ppolicy forwarded bind failure messages cause success
- fix: CVE-2011-1025 rootpw is not verified for ndb backend</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:59.506-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:17.712-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.226-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:55:38.270-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:55:38.270-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openldap is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:134181"/>
          <criterion comment="compat-openldap is earlier than 0:2.4.19_2.3.43-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:134183"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:134014"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:134217"/>
          <criterion comment="openldap-servers is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:134210"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:133900"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28070" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0407 -- logrotate security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>logrotate</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0407.html" ref_id="ELSA-2011-0407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1098" ref_id="CVE-2011-1098"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1154" ref_id="CVE-2011-1154"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1155" ref_id="CVE-2011-1155"/>
        <description>[3.7.8-12.1]
- fix #688518 - fixed CVE-2011-1154, CVE-2011-1155
  and CVE-2011-1098</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:53">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:57.638-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:17.407-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:28.063-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:39:37.744-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:39:37.744-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="logrotate is earlier than 0:3.7.8-12.el6_0.1" test_ref="oval:org.mitre.oval:tst:134120"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28066" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0320 -- libcgroup security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libcgroup</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0320.html" ref_id="ELSA-2011-0320"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1006" ref_id="CVE-2011-1006"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1022" ref_id="CVE-2011-1022"/>
        <description>[0.36-6.1]
- Fixed buffer overflow when parsing cgexec command line parameters.
- Added checking of source of netlink messages to cgrulesengd daemon.
- Resolves: CVE-2011-1006 CVE-2011-1022</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:52.571-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:17.175-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:27.916-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:42:27.789-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:42:27.789-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libcgroup is earlier than 0:0.36.1-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134166"/>
          <criterion comment="libcgroup-devel is earlier than 0:0.36.1-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:133836"/>
          <criterion comment="libcgroup-pam is earlier than 0:0.36.1-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:134192"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28065" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0498 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0498.html" ref_id="ELSA-2011-0498"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4250" ref_id="CVE-2010-4250"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4565" ref_id="CVE-2010-4565"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4649" ref_id="CVE-2010-4649"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0006" ref_id="CVE-2011-0006"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0711" ref_id="CVE-2011-0711"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0712" ref_id="CVE-2011-0712"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0726" ref_id="CVE-2011-0726"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1013" ref_id="CVE-2011-1013"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1016" ref_id="CVE-2011-1016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1019" ref_id="CVE-2011-1019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1044" ref_id="CVE-2011-1044"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1079" ref_id="CVE-2011-1079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1080" ref_id="CVE-2011-1080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1093" ref_id="CVE-2011-1093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1573" ref_id="CVE-2011-1573"/>
        <description>[2.6.32-71.29.1.el6]
- [mm] Revert '[mm] pdpte registers are not flushed when PGD entry is changed in x86 PAE mode' (Larry Woodman) [695256 691310]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:52.887-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:16.970-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:27.799-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:05:35.467-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:05:35.467-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:134087"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:133471"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:133827"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:133344"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:133990"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:133903"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:133952"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:133899"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28057" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0959 -- mutt security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mutt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0959.html" ref_id="ELSA-2011-0959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1429" ref_id="CVE-2011-1429"/>
        <description>[1.5.20-2.20091214hg736b6a.el6_1.1]
- Fixed hostname verification of x.509 certificates.
  Resolves: #716889 (CVE-2011-1429)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:30.895-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:15.825-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:26.924-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:05:13.127-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:05:13.127-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="mutt is earlier than 0:1.5.20-2.20091214hg736b6a.el6_1.1" test_ref="oval:org.mitre.oval:tst:133694"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28054" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0214 -- java-1.6.0-openjdk security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0214.html" ref_id="ELSA-2011-0214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4476" ref_id="CVE-2010-4476"/>
        <description>[1.6.0.0-1.36.b17]

- removed plugin. How it comes in?!

- Resolves: rhbz#676295



[1.6.0.0-1.33.b17]

- bumped release number, it was accidentaly reduced, and now lower version then last one was released.

- Resolves: rhbz#676295



[1.6.0.0-1.22.b17]

- Updated to 1.7.9 tarball

- removed patch6, fixed upstrream

- Resolves: rhbz#676295</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:44.385-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:15.647-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:26.824-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:30:29.394-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:30:29.394-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:133898"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134051"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134180"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:133486"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.18.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134086"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134273"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134257"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133922"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134233"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133839"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28051" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0969 -- thunderbird security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0969.html" ref_id="ELSA-2010-0969"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3768" ref_id="CVE-2010-3768"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3776" ref_id="CVE-2010-3776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3777" ref_id="CVE-2010-3777"/>
        <description>[3.1.7-3.0.1.el6]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[3.1.7-3]
- Update to 3.1.7 build3

[3.1.7-2]
- Update to 3.1.7 build2

[3.1.7-1]
- Update to 3.1.7

[3.1.6-1]
- Update to 3.1.6

[3.1.5-1]
- Update to 3.1.5</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:04.629-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:14.841-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:26.363-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:46:44.144-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:46:44.144-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:3.1.7-3.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134398"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28049" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1526 -- glibc security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1526.html" ref_id="ELSA-2011-1526"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5064" ref_id="CVE-2009-5064"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1089" ref_id="CVE-2011-1089"/>
        <description>A flaw was found in the way the ldd utility identified dynamically linked
libraries. If an attacker could trick a user into running ldd on a
malicious binary, it could result in arbitrary code execution with the
privileges of the user running ldd. (CVE-2009-5064)

It was found that the glibc addmntent() function, used by various mount
helper utilities, did not handle certain errors correctly when updating the
mtab (mounted file systems table) file. If such utilities had the setuid
bit set, a local attacker could use this flaw to corrupt the mtab file.
(CVE-2011-1089)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:06.608-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:14.728-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:26.285-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:132940"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:133032"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:132859"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:132727"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:133087"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:133131"/>
          <criterion comment="nscd is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:133075"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28045" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0599 -- sudo security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0599.html" ref_id="ELSA-2011-0599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0010" ref_id="CVE-2011-0010"/>
        <description>[1.7.4p5-5]
- patch: log failed user role changes
  Resolves: rhbz#665131

[1.7.4p5-4]
- added #includedir /etc/sudoers.d to sudoers
  Resolves: rhbz#615087

[1.7.4p5-3]
- added !visiblepw option to sudoers
  Resolves: rhbz#688640

[1.7.4p5-2]
- added patch for rhbz#665131
  Resolves: rhbz#665131

[1.7.4p5-1]
- rebase to latest stable version
- sudo now uses /var/db/sudo for timestamps
- new command available: sudoreplay
- use native audit support
- sync configuration paths with the nss_ldap package
  Resolves: rhbz#615087
  Resolves: rhbz#652726
  Resolves: rhbz#634159
  Resolves: rhbz#603823</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:41.155-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:14.343-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:26.106-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:53:42.944-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:53:42.944-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="sudo is earlier than 0:1.7.4p5-5.el6" test_ref="oval:org.mitre.oval:tst:133979"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28043" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1189 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1189.html" ref_id="ELSA-2011-1189"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1182" ref_id="CVE-2011-1182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1576" ref_id="CVE-2011-1576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1593" ref_id="CVE-2011-1593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1776" ref_id="CVE-2011-1776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1898" ref_id="CVE-2011-1898"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2183" ref_id="CVE-2011-2183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2213" ref_id="CVE-2011-2213"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2491" ref_id="CVE-2011-2491"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2492" ref_id="CVE-2011-2492"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2495" ref_id="CVE-2011-2495"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2497" ref_id="CVE-2011-2497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2517" ref_id="CVE-2011-2517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2689" ref_id="CVE-2011-2689"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2695" ref_id="CVE-2011-2695"/>
        <description>[2.6.32-131.12.1.el6]
- [netdrv] be2net: clear intr bit in be_probe() (Ivan Vecera) [726308 722596]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:22.018-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:13.983-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:25.946-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:54:40.684-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:54:40.684-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:133179"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:133559"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:133303"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:133549"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:133219"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:133578"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:133243"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:133424"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28042" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0918 -- cvs security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cvs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0918.html" ref_id="ELSA-2010-0918"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3846" ref_id="CVE-2010-3846"/>
        <description>[1.11.23-11.el6_0.1]
- Fix CVE-2010-3846 (Resolves: #644813)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:03.585-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:13.815-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:25.846-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:40:58.322-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:40:58.322-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="cvs is earlier than 0:1.11.23-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:134389"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28038" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2024 -- Oracle Linux 6 Unbreakable Enterprise kernel security and bug fix
          update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2024.html" ref_id="ELSA-2011-2024"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1767" ref_id="CVE-2011-1767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1768" ref_id="CVE-2011-1768"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2213" ref_id="CVE-2011-2213"/>
        <description>[2.6.32-200.16.1.el6uek] - Revert change to restore DEFAULTKERNEL</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:35.477-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:13.403-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:25.544-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:133034 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:56.649-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:44.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel-uek is earlier than 0:2.6.32-200.16.1.el6uek" test_ref="oval:org.mitre.oval:tst:132742"/>
          <criterion comment="ofa-2.6.32-200.16.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133034"/>
          <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-200.16.1.el6uek" test_ref="oval:org.mitre.oval:tst:133215"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-200.16.1.el6uek" test_ref="oval:org.mitre.oval:tst:133204"/>
          <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-200.16.1.el6uek" test_ref="oval:org.mitre.oval:tst:133613"/>
          <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-200.16.1.el6uek" test_ref="oval:org.mitre.oval:tst:132625"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-200.16.1.el6uek" test_ref="oval:org.mitre.oval:tst:133029"/>
          <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-200.16.1.el6uek" test_ref="oval:org.mitre.oval:tst:133430"/>
          <criterion comment="ofa-2.6.32-200.16.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133158"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28033" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1166 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1166.html" ref_id="ELSA-2011-1166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0084" ref_id="CVE-2011-0084"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2378" ref_id="CVE-2011-2378"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2982" ref_id="CVE-2011-2982"/>
        <description>[3.1.12-1.0.1.el6_1]
- Replaced thunderbird-redhat-default-prefs.js with
  thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[3.1.12-1]
- Update to 3.1.12</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:23.600-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:12.993-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:25.295-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:54:30.041-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:54:30.041-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:3.1.12-1.0.1.el6_1" test_ref="oval:org.mitre.oval:tst:133596"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28032" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0554 -- python security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python</product>
          <product>python-docs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0554.html" ref_id="ELSA-2011-0554"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3493" ref_id="CVE-2010-3493"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1015" ref_id="CVE-2011-1015"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1521" ref_id="CVE-2011-1521"/>
        <description>python:
[2.6.6-20]
Resolves: CVE-2010-3493</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:10.180-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:12.655-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:25.104-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:26:06.593-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:26:06.593-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="python is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:134024"/>
          <criterion comment="python-docs is earlier than 0:2.6.6-2.el6" test_ref="oval:org.mitre.oval:tst:133907"/>
          <criterion comment="python-devel is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:133781"/>
          <criterion comment="python-libs is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:133450"/>
          <criterion comment="python-test is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:133697"/>
          <criterion comment="python-tools is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:134077"/>
          <criterion comment="tkinter is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:133752"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28029" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0923 -- dhcp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0923.html" ref_id="ELSA-2010-0923"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3611" ref_id="CVE-2010-3611"/>
        <description>[12:4.1.1-12.P1.1]
- CVE-2010-3611: NULL pointer dereference crash via crafted DHCPv6 packet (#651913)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:44.033-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:12.312-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:24.943-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:16:45.053-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:16:45.053-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dhcp is earlier than 0:4.1.1-12.P1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134492"/>
          <criterion comment="dhclient is earlier than 0:4.1.1-12.P1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134600"/>
          <criterion comment="dhcp-devel is earlier than 0:4.1.1-12.P1.el6_0.1" test_ref="oval:org.mitre.oval:tst:134562"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28027" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1911 -- ruby security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1911.html" ref_id="ELSA-2014-1911"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8080" ref_id="CVE-2014-8080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8090" ref_id="CVE-2014-8090"/>
        <description>[1.8.7.374-3]
- Fix REXML billion laughs attack via parameter entity expansion
  (CVE-2014-8080).
  Resolves: rhbz#1163993
- REXML incomplete fix for CVE-2014-8080 (CVE-2014-8090).
  Resolves: rhbz#1163993</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:26.168-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:19.389-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:21.562-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135580"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135347"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135826"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135719"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:136029"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:136020"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135979"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135577"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135995"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28024" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0677 -- openssl security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0677.html" ref_id="ELSA-2011-0677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0014" ref_id="CVE-2011-0014"/>
        <description>[1.0.0-10]
- fix OCSP stapling vulnerability - CVE-2011-0014 (#676063)
- correct the README.FIPS document

[1.0.0-8]
- add -x931 parameter to openssl genrsa command to use the ANSI X9.31
  key generation method
- use FIPS-186-3 method for DSA parameter generation
- add OPENSSL_FIPS_NON_APPROVED_MD5_ALLOW environment variable
  to allow using MD5 when the system is in the maintenance state
  even if the /proc fips flag is on
- make openssl pkcs12 command work by default in the FIPS mode

[1.0.0-7]
- listen on ipv6 wildcard in s_server so we accept connections
  from both ipv4 and ipv6 (#601612)
- fix openssl speed command so it can be used in the FIPS mode
  with FIPS allowed ciphers (#619762)

[1.0.0-6]
- disable code for SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG - CVE-2010-3864
  (#649304)

[1.0.0-5]
- fix race in extension parsing code - CVE-2010-3864 (#649304)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:39">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:45.351-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:11.964-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:24.703-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:50:51.417-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:50:51.417-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:133525"/>
          <criterion comment="openssl-devel is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:133831"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:133771"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:133653"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28023" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0892 -- openswan security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0892.html" ref_id="ELSA-2010-0892"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3302" ref_id="CVE-2010-3302"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3308" ref_id="CVE-2010-3308"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3752" ref_id="CVE-2010-3752"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3753" ref_id="CVE-2010-3753"/>
        <description>[2.6.24-8.1]
Resolves: #635058 CVE-2010-3302 CVE-2010-3308
                  CVE-2010-2752 CVE-2010-3753</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:43.161-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:11.537-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:24.506-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:14:32.328-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:14:32.328-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openswan is earlier than 0:2.6.24-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:134200"/>
          <criterion comment="openswan-doc is earlier than 0:2.6.24-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:134428"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28020" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0886 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0886.html" ref_id="ELSA-2011-0886"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0083" ref_id="CVE-2011-0083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0085" ref_id="CVE-2011-0085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2362" ref_id="CVE-2011-2362"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2363" ref_id="CVE-2011-2363"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2364" ref_id="CVE-2011-2364"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2365" ref_id="CVE-2011-2365"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2374" ref_id="CVE-2011-2374"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2375" ref_id="CVE-2011-2375"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2376" ref_id="CVE-2011-2376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2377" ref_id="CVE-2011-2377"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2605" ref_id="CVE-2011-2605"/>
        <description>[3.1.11-1.0.1.el6_1]
- Replaced thunderbird-redhat-default-prefs.js with
  thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[3.1.11-2]
- Update to 3.1.11</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:30.181-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:10.510-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:24.107-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:56:16.923-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:56:16.923-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:3.1.11-2.0.1.el6_1" test_ref="oval:org.mitre.oval:tst:132910"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28019" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0007 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0007.html" ref_id="ELSA-2011-0007"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3298" ref_id="CVE-2010-3298"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3301" ref_id="CVE-2010-3301"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3432" ref_id="CVE-2010-3432"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3437" ref_id="CVE-2010-3437"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3442" ref_id="CVE-2010-3442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3477" ref_id="CVE-2010-3477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3698" ref_id="CVE-2010-3698"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3705" ref_id="CVE-2010-3705"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3861" ref_id="CVE-2010-3861"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3865" ref_id="CVE-2010-3865"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3874" ref_id="CVE-2010-3874"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3876" ref_id="CVE-2010-3876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3880" ref_id="CVE-2010-3880"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3904" ref_id="CVE-2010-3904"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4072" ref_id="CVE-2010-4072"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4073" ref_id="CVE-2010-4073"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4074" ref_id="CVE-2010-4074"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4075" ref_id="CVE-2010-4075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4077" ref_id="CVE-2010-4077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4079" ref_id="CVE-2010-4079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4080" ref_id="CVE-2010-4080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4081" ref_id="CVE-2010-4081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4082" ref_id="CVE-2010-4082"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4083" ref_id="CVE-2010-4083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2492" ref_id="CVE-2010-2492"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2803" ref_id="CVE-2010-2803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2955" ref_id="CVE-2010-2955"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2962" ref_id="CVE-2010-2962"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3067" ref_id="CVE-2010-3067"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3078" ref_id="CVE-2010-3078"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3079" ref_id="CVE-2010-3079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3080" ref_id="CVE-2010-3080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3081" ref_id="CVE-2010-3081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3084" ref_id="CVE-2010-3084"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4158" ref_id="CVE-2010-4158"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4160" ref_id="CVE-2010-4160"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4162" ref_id="CVE-2010-4162"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4163" ref_id="CVE-2010-4163"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4242" ref_id="CVE-2010-4242"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4248" ref_id="CVE-2010-4248"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4249" ref_id="CVE-2010-4249"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4263" ref_id="CVE-2010-4263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4525" ref_id="CVE-2010-4525"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4668" ref_id="CVE-2010-4668"/>
        <description>[2.6.32-71.14.1.0.1.el6]
- replace Red Hat with Oracle in files genkey and kernel.spec</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:00.449-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:07.999-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:23.336-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:40:29.226-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:40:29.226-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:133389"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:134349"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:133778"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:133845"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:134115"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:134319"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:133823"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:133747"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28014" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0447 -- krb5 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0447.html" ref_id="ELSA-2011-0447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0285" ref_id="CVE-2011-0285"/>
        <description>[1.8.2-3.7]
- kadmind: add upstream patch to fix free() on an invalid pointer (#696341,
  MITKRB5-SA-2011-004, CVE-2011-0285)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:49.340-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:07.821-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:23.221-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:38:39.257-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:38:39.257-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:133879"/>
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:133132"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:133947"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:133350"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:133890"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:133817"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:133997"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28013" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0433 -- xorg-x11-server-utils security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0433.html" ref_id="ELSA-2011-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0465" ref_id="CVE-2011-0465"/>
        <description>[7.4-15.el6_0.1]
- cve-2011-0465: Sanitize cpp macro expansion. (CVE 2011-0465)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:01.728-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:07.663-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:23.096-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:22:26.149-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:22:26.149-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="xorg-x11-server-utils is earlier than 0:7.1-5.el5_6.1" test_ref="oval:org.mitre.oval:tst:133141"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="xorg-x11-server-utils is earlier than 0:7.4-15.el6_0.1" test_ref="oval:org.mitre.oval:tst:133795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28011" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1197 -- libvirt security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1197.html" ref_id="ELSA-2011-1197"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2511" ref_id="CVE-2011-2511"/>
        <description>[0.8.7-18.0.1.el6_1.1 ]
- Replace docs/et.png in tarball with blank image

[libvirt-0.8.7-18.el6_1.1]
- debug: Avoid null dereference on uuid lookup api (rhbz#728546)
- Fix auditing of disk hotunplug operations (rhbz#728516)
- storage: Fix regression with backing format (rhbz#726617)
- Fix performance problem of virStorageVolCreateXMLFrom() (rhbz#715400)
- qemu: Translate boot config into bootindex if possible (rhbz#715401)
- remote: Protect against integer overflow (rhbz#717202)
Resolves: rhbz#728546, rhbz#728516, rhbz#715400, rhbz#715401, rhbz#717202
Resolves: rhbz#726617</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:21.400-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:07.238-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:22.867-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:36:10.560-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:36:10.560-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.8.7-18.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133500"/>
          <criterion comment="libvirt-client is earlier than 0:0.8.7-18.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133526"/>
          <criterion comment="libvirt-devel is earlier than 0:0.8.7-18.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133180"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.7-18.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133529"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28010" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0200 -- krb5 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0200.html" ref_id="ELSA-2011-0200"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4020" ref_id="CVE-2010-4020"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4022" ref_id="CVE-2010-4022"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1322" ref_id="CVE-2010-1322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1323" ref_id="CVE-2010-1323"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1324" ref_id="CVE-2010-1324"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0281" ref_id="CVE-2011-0281"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0282" ref_id="CVE-2011-0282"/>
        <description>[1.8.2-3.4]
- add upstream patches to fix standalone kpropd exiting if the per-client
  child process exits with an error, and hang or crash in the KDC when using
  the LDAP kdb backend (CVE-2010-4022, CVE-2011-0281, CVE-2011-0282, #671101)

[1.8.2-3.3]
- pull up crypto changes made between 1.8.2 and 1.8.3 to fix upstream #6751,
  assumed to already be there for the next fix
- incorporate candidate patch to fix various issues from MITKRB5-SA-2010-007
  (CVE-2010-1323, CVE-2010-1324, CVE-2010-4020, #651962)

[1.8.2-3.2]
- fix reading of keyUsage extensions when attempting to select pkinit client
  certs (part of #644825, RT#6775)
- fix selection of pkinit client certs when one or more don't include a
  subjectAltName extension (part of #644825, RT#6774)

[1.8.2-3.1]
- incorporate candidate patch to fix uninitialized pointer crash in the KDC
  (CVE-2010-1322, #636336)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:12.574-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:06.616-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:22.557-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:57:53.554-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:57:53.554-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:134331"/>
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:134179"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:134008"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:134297"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:134371"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:133844"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:134248"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28007" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1635 -- cups security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1635.html" ref_id="ELSA-2011-1635"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2896" ref_id="CVE-2011-2896"/>
        <description>[1.4.2-44]
- Init script should source /etc/sysconfig/cups (bug #744791)

[1.4.2-43]
- The scheduler might leave old job data files in the spool directory
  (STR #3795, STR #3880, bug #735505).

[1.4.2-42]
- A further fix for imageto* filters crashing with bad GIF files
  (STR #3914, bug #714118).

[1.4.2-41]
- The imageto* filters could crash with bad GIF files (STR #3867, bug #714118).

[1.4.2-40]
- Map ASCII to ISO-8859-1 in the transcoding code (STR #3832, bug #681836).
- Check for empty values for some configuration directives (STR #3861, bug #706673).
- The network backends no longer try to collect SNMP supply and status
  information for raw queues (STR #3809, bug #709896).
- Handle EAI_NONAME when resolving hostnames (bug #712430).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:15.039-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:06.162-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:22.297-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:133126"/>
          <criterion comment="cups-devel is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:133044"/>
          <criterion comment="cups-libs is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:132758"/>
          <criterion comment="cups-lpd is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:133064"/>
          <criterion comment="cups-php is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:132895"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28000" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0919 -- qemu-kvm security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0919.html" ref_id="ELSA-2011-0919"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2212" ref_id="CVE-2011-2212"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2512" ref_id="CVE-2011-2512"/>
        <description>[qemu-kvm-0.12.1.2-2.160.el6_1.2]
- kvm-virtio-guard-against-negative-vq-notifies.patch [bz#717403]
- Resolves: bz#717403
  (qemu-kvm: OOB memory access caused by negative vq notifies [rhel-6.1.z])

[qemu-kvm-0.12.1.2-2.160.el6_1]
- kvm-Fix-phys-memory-client-pass-guest-physical-address-n.patch [bz#701771]
- kvm-virtio-prevent-indirect-descriptor-buffer-overflow.patch [bz#713592]
- Resolves: bz#701771
  (Fix phys memory client for vhost)
- Resolves: bz#713592
  (EMBARGOED CVE-2011-2212 virtqueue: too-large indirect descriptor buffer overflow [rhel-6.1.z])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:42.092-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:04.721-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.608-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:18:18.963-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:18:18.963-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.160.el6_1.2" test_ref="oval:org.mitre.oval:tst:133713"/>
          <criterion comment="qemu-img is earlier than 0:0.12.1.2-2.160.el6_1.2" test_ref="oval:org.mitre.oval:tst:133763"/>
          <criterion comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.160.el6_1.2" test_ref="oval:org.mitre.oval:tst:133746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27999" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0926 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind97</product>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0926.html" ref_id="ELSA-2011-0926"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2464" ref_id="CVE-2011-2464"/>
        <description>[32:9.7.3-2.2.P3]

- update to 9.7.3-P3 (CVE-2011-2464)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:18.835-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:04.475-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.473-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:20:29.658-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:20:29.658-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind97 is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133598"/>
            <criterion comment="bind97-chroot is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133480"/>
            <criterion comment="bind97-devel is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133668"/>
            <criterion comment="bind97-libs is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133708"/>
            <criterion comment="bind97-utils is earlier than 0:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:133325"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133637"/>
            <criterion comment="bind-chroot is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133735"/>
            <criterion comment="bind-devel is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133661"/>
            <criterion comment="bind-libs is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133189"/>
            <criterion comment="bind-sdb is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:133066"/>
            <criterion comment="bind-utils is earlier than 0:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:132772"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27998" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0154 -- hplip security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>hplip</product>
          <product>hplip3</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0154.html" ref_id="ELSA-2011-0154"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4267" ref_id="CVE-2010-4267"/>
        <description>[3.9.8-33:.1]

- Applied patch to fix CVE-2010-4267, remote stack overflow

  vulnerability (bug #662740).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:39.736-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:04.258-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.326-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:36:05.835-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:36:05.835-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="hplip is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:134219"/>
            <criterion comment="hplip3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134590"/>
            <criterion comment="hpijs is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:134122"/>
            <criterion comment="hpijs3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134457"/>
            <criterion comment="hplip3-common is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134701"/>
            <criterion comment="hplip3-gui is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134279"/>
            <criterion comment="hplip3-libs is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134467"/>
            <criterion comment="libsane-hpaio is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:134689"/>
            <criterion comment="libsane-hpaio3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:134702"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="hplip is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134255"/>
            <criterion comment="hpijs is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134744"/>
            <criterion comment="hplip-common is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134433"/>
            <criterion comment="hplip-gui is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134584"/>
            <criterion comment="hplip-libs is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134640"/>
            <criterion comment="libsane-hpaio is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:134687"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27995" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1536 -- sos security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sos</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1536.html" ref_id="ELSA-2011-1536"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4083" ref_id="CVE-2011-4083"/>
        <description>The sosreport utility incorrectly included Certificate-based Red Hat
Network private entitlement keys in the resulting archive of debugging
information. An attacker able to access the archive could use the keys to
access Red Hat Network content available to the host. This issue did not
affect users of Red Hat Network Classic. (CVE-2011-4083)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:07.093-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:04.071-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:21.181-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:45:17.661-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:45:17.661-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="sos is earlier than 0:2.2-17.0.1.el6" test_ref="oval:org.mitre.oval:tst:132917"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27993" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1615 -- virt-v2v security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>virt-v2v</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1615.html" ref_id="ELSA-2011-1615"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1773" ref_id="CVE-2011-1773"/>
        <description>[0.8.3-5]
- Fix regression when converting Win7 32 bit to RHEV (RHBZ#738236)

[0.8.3-4]
[element]

[0.8.3-3]
- Add missing dependency on new Sys::Virt

[0.8.3-2]
- Fix for CVE-2011-1773
- Document limitations wrt Windows Recovery Console

[0.8.3-1]
- Include missing virt-v2v.db
- Rebase to upstream release 0.8.3

[0.8.2-2]
- Split configuration into /etc/virt-v2v.conf and /var/lib/virt-v2v/virt-v2v.db
- Improve usability as non-root user (RHBZ#671094)
- Update man pages to use -os as appropriate (RHBZ#694370)
- Warn if user specifies both -n and -b (RHBZ#700759)
- Fix cleanup when multiboot OS is detected (RHBZ#702007)
- Ensure the cirrus driver is installed if required (RHBZ#708961)
- Remove unnecessary dep on perl(IO::Handle)
- Fix conversion of xen guests using aio storage backend.
- Suppress warning for chainloader grub entries.
- Only configure a single scsi_hostadapter for converted VMware guests.

[0.8.2-1]
- Rebase to upstream release 0.8.2

[0.7.1-4]
- Fix detection of Windows XP Pro x64 (RHBZ#679017)
- Fix error message when converting Red Hat Desktop (RHBZ#678950)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:29.950-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:03.636-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:20.971-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="virt-v2v is earlier than 0:0.8.3-5.el6" test_ref="oval:org.mitre.oval:tst:132762"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27989" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1379 -- krb5 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1379.html" ref_id="ELSA-2011-1379"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1527" ref_id="CVE-2011-1527"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1528" ref_id="CVE-2011-1528"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1529" ref_id="CVE-2011-1529"/>
        <description>[1.9-9.2]
- apply upstream patch to fix a null pointer derference with the LDAP kdb
  backend (CVE-2011-1527), an assertion failure with multiple kdb backends
  (CVE-2011-1528), and a null pointer dereference with multiple kdb backends
  (CVE-2011-1529) (#740084)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:28.192-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:03.140-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:20.744-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:59:43.929-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:59:43.929-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:133370"/>
          <criterion comment="krb5-devel is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:133337"/>
          <criterion comment="krb5-libs is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:133251"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:132887"/>
          <criterion comment="krb5-server is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:132899"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:133079"/>
          <criterion comment="krb5-workstation is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:133361"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27988" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0309 -- pango security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pango</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0309.html" ref_id="ELSA-2011-0309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0064" ref_id="CVE-2011-0064"/>
        <description>[1.28.1-3.el6_0.5]
- Prevent an integer overflow in hb_buffer_ensure()
Related: #679693

[1.28.1-3.el6_0.4]
- Check for realloc failures in hb_buffer_ensure() (CVE-2011-0064)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:45.953-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:02.941-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:20.664-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:57:21.531-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:57:21.531-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pango is earlier than 0:1.28.1-3.el6_0.5" test_ref="oval:org.mitre.oval:tst:133779"/>
          <criterion comment="pango-devel is earlier than 0:1.28.1-3.el6_0.5" test_ref="oval:org.mitre.oval:tst:133880"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27985" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0975 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0975.html" ref_id="ELSA-2010-0975"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3613" ref_id="CVE-2010-3613"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3614" ref_id="CVE-2010-3614"/>
        <description>[32:9.7.0-5.P2.1]
- fix CVE-2010-3613 and CVE-2010-3614</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:07.073-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:02.664-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:20.510-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:41:18.019-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:41:18.019-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 0:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134018"/>
          <criterion comment="bind-chroot is earlier than 0:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134153"/>
          <criterion comment="bind-devel is earlier than 0:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134348"/>
          <criterion comment="bind-libs is earlier than 0:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:133973"/>
          <criterion comment="bind-sdb is earlier than 0:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134208"/>
          <criterion comment="bind-utils is earlier than 0:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134284"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27978" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1821 -- pidgin security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1821.html" ref_id="ELSA-2011-1821"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4601" ref_id="CVE-2011-4601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4602" ref_id="CVE-2011-4602"/>
        <description>[2.7.9-3.el6_2.2]
- Add patch for CVE-2011-4602 (RH bug #766452).

[2.7.9-3.el6_2.1]
- Add patch for CVE-2011-4601 (RH bug #766452).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:17.765-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:01.964-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:20.119-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:59:19.129-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:59:19.129-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pidgin is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:133007"/>
          <criterion comment="finch is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:132880"/>
          <criterion comment="finch-devel is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:132948"/>
          <criterion comment="libpurple is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:132789"/>
          <criterion comment="libpurple-devel is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:132792"/>
          <criterion comment="libpurple-perl is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:132735"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:132322"/>
          <criterion comment="pidgin-devel is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:133012"/>
          <criterion comment="pidgin-docs is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:133065"/>
          <criterion comment="pidgin-perl is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:132961"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27976" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0018 -- libxml2 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0018.html" ref_id="ELSA-2012-0018"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3905" ref_id="CVE-2011-3905"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3919" ref_id="CVE-2011-3919"/>
        <description>[2.7.6-4.0.1.el6_2.1]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[2.7.6-4.el6_2.1]
- Make sure the parser returns when getting a Stop order CVE-2011-3905
- Fix an allocation error when copying entities CVE-2011-3919
- Resolves: rhbz#771913</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:26.326-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:01.874-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:20.032-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:44:32.444-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:44:32.444-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libxml2 is earlier than 0:2.7.6-4.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132333"/>
          <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132842"/>
          <criterion comment="libxml2-python is earlier than 0:2.7.6-4.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132967"/>
          <criterion comment="libxml2-static is earlier than 0:2.7.6-4.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132079"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27975" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1852 -- krb5-appl security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5-appl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1852.html" ref_id="ELSA-2011-1852"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4862" ref_id="CVE-2011-4862"/>
        <description>[1.0.1-7]
- Correct patch, bump release

[1.0.1-6]
- Fix for CVE-2011-4862</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:44:59.537-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:01.704-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:19.903-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:06:38.781-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:06:38.781-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5-appl is earlier than 0:1.0.1-7.el6_2" test_ref="oval:org.mitre.oval:tst:132780"/>
          <criterion comment="krb5-appl-clients is earlier than 0:1.0.1-7.el6_2" test_ref="oval:org.mitre.oval:tst:132979"/>
          <criterion comment="krb5-appl-servers is earlier than 0:1.0.1-7.el6_2" test_ref="oval:org.mitre.oval:tst:132663"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27974" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3089 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3089.html" ref_id="ELSA-2014-3089"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3687" ref_id="CVE-2014-3687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3673" ref_id="CVE-2014-3673"/>
        <description>kernel-uek [2.6.32-400.36.11uek] - net: sctp: fix panic on duplicate ASCONF
          chunks (Daniel Borkmann) [Orabug: 20010592] {CVE-2014-3687} - net: sctp: fix
          skb_over_panic when receiving malformed ASCONF chunks (Daniel Borkmann) [Orabug: 20010579]
          {CVE-2014-3673}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:10:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-17T19:58:44.746-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:51.824-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:22.217-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:134812 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:52.595-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:41.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135550"/>
            <criterion comment="mlnx_en-2.6.32-400.36.11.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:135609"/>
            <criterion comment="ofa-2.6.32-400.36.11.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:135618"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135374"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135487"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135522"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:134639"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135156"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.11.el5uek" test_ref="oval:org.mitre.oval:tst:135388"/>
            <criterion comment="mlnx_en-2.6.32-400.36.11.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:134812"/>
            <criterion comment="ofa-2.6.32-400.36.11.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:135617"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135259"/>
            <criterion comment="mlnx_en-2.6.32-400.36.11.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:135496"/>
            <criterion comment="ofa-2.6.32-400.36.11.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:134971"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135529"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135614"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135147"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135563"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135480"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.11.el6uek" test_ref="oval:org.mitre.oval:tst:135199"/>
            <criterion comment="mlnx_en-2.6.32-400.36.11.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:135375"/>
            <criterion comment="ofa-2.6.32-400.36.11.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:135192"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27972" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1780 -- tomcat6 security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1780.html" ref_id="ELSA-2011-1780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1184" ref_id="CVE-2011-1184"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2204" ref_id="CVE-2011-2204"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2526" ref_id="CVE-2011-2526"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3190" ref_id="CVE-2011-3190"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5062" ref_id="CVE-2011-5062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5063" ref_id="CVE-2011-5063"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5064" ref_id="CVE-2011-5064"/>
        <description>[0:6.0.24-35]
- Resolves: cve-2011-3190
- Resolves: cve-2011-2204
- Resolves: cve-2011-2526
- Resolves: cve-2011-1184
- Resolves: rhbz 748807 - tomcat6 broken when LANG=fr</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:21.137-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:01.368-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:19.651-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:56:00.113-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:56:00.113-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:132240"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:133190"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:132896"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:132794"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:132911"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:133214"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:132366"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:133185"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:132898"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27971" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1342 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1342.html" ref_id="ELSA-2011-1342"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2372" ref_id="CVE-2011-2372"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2995" ref_id="CVE-2011-2995"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2998" ref_id="CVE-2011-2998"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2999" ref_id="CVE-2011-2999"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3000" ref_id="CVE-2011-3000"/>
        <description>[3.1.15-1.0.1.el6_1]
- Replaced thunderbird-redhat-default-prefs.js with
  thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[3.1.15-1]
- Update to 3.1.15</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:23.815-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:07:00.902-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:19.464-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:41:27.747-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:41:27.747-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:3.1.15-1.0.1.el6_1" test_ref="oval:org.mitre.oval:tst:132740"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27967" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0479 -- libvirt security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0479.html" ref_id="ELSA-2011-0479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1486" ref_id="CVE-2011-1486"/>
        <description>[0.8.1-27.0.1.el6_0.6]
- Replace docs/et.png in tarball with blank image

[0.8.1-27.el6_0.6]
- Properly initialize supplementary groups for qemu process (rhbz#668692)
- Make error reporting in libvirtd thread safe (CVE-2011-1486)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:45.763-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:59.947-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:19.108-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:43:05.424-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:43:05.424-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.8.1-27.0.1.el6_0.6" test_ref="oval:org.mitre.oval:tst:133870"/>
          <criterion comment="libvirt-client is earlier than 0:0.8.1-27.0.1.el6_0.6" test_ref="oval:org.mitre.oval:tst:134047"/>
          <criterion comment="libvirt-devel is earlier than 0:0.8.1-27.0.1.el6_0.6" test_ref="oval:org.mitre.oval:tst:133473"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.1-27.0.1.el6_0.6" test_ref="oval:org.mitre.oval:tst:133759"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27966" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0281 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0281.html" ref_id="ELSA-2011-0281"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4448" ref_id="CVE-2010-4448"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4450" ref_id="CVE-2010-4450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4465" ref_id="CVE-2010-4465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4469" ref_id="CVE-2010-4469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4470" ref_id="CVE-2010-4470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4472" ref_id="CVE-2010-4472"/>
        <description>[1.6.0.0-1.39.b17]
- respin of  IcedTea6 1.7.10
- Resolves: rhbz#676276

[1.6.0.0-1.37.b17]
- Updated to IcedTea6 1.7.10
- Resolves: rhbz#676276</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:43.616-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:59.277-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:18.870-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:30:06.829-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:30:06.829-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134038"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134243"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134268"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134261"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.20.b17.0.1.el5" test_ref="oval:org.mitre.oval:tst:134283"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134238"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133438"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133466"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:134011"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:133975"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27964" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0009 -- evince security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>evince</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0009.html" ref_id="ELSA-2011-0009"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2640" ref_id="CVE-2010-2640"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2641" ref_id="CVE-2010-2641"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2642" ref_id="CVE-2010-2642"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2643" ref_id="CVE-2010-2643"/>
        <description>[2.28.2-14.el6_0.1]
- Fixes CVE-2010-2640, CVE-2010-2641, CVE-2010-2642 and CVE-2010-2643
- Resolves: #666323</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:05.153-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:58.663-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:18.593-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:21:38.951-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:21:38.951-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="evince is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:134419"/>
          <criterion comment="evince-devel is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:134245"/>
          <criterion comment="evince-dvi is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:134244"/>
          <criterion comment="evince-libs is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:134342"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27961" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0910 -- ruby security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0910.html" ref_id="ELSA-2011-0910"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0188" ref_id="CVE-2011-0188"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1004" ref_id="CVE-2011-1004"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1005" ref_id="CVE-2011-1005"/>
        <description>[1.8.7.299-7.1]
- Address CVE-2011-1004 'Symlink race condition by removing directory trees in
  fileutils module'
  * ruby-1.8.7-CVE-2011-1004.patch
- Address CVE-2011-1005 'Untrusted codes able to modify arbitrary strings'
  * ruby-1.8.7-CVE-2011-1005.patch
- Address CVE-2011-0188 'memory corruption in BigDecimal on 64bit platforms'
  * ruby-1.8.7-CVE-2011-0188.patch
- Resolves: rhbz#709963</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:21.125-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:58.148-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:18.285-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:11:49.753-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:11:49.753-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:133686"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:133404"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:133700"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:133144"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:133276"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:133527"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:133447"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:133368"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:133547"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27955" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2038 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
          <product>mlnx_en</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2038.html" ref_id="ELSA-2011-2038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1576" ref_id="CVE-2011-1576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4127" ref_id="CVE-2011-4127"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1493" ref_id="CVE-2011-1493"/>
        <description>kernel-uek [2.6.32-300.4.1.el6uek] - [pci] intel-iommu: Default to non-coherent
          for domains unattached to iommus (Joe Jin) - [dm] do not forward ioctls from logical
          volumes to the underlying device (Joe Jin) {CVE-2011-4127} - [block] fail SCSI passthrough
          ioctls on partition devices (Joe Jin) {CVE-2011-4127} - [block] add and use
          scsi_blk_cmd_ioctl (Joe Jin) {CVE-2011-4127} - [net] gro: reset vlan_tci on reuse (Dan
          Carpenter) {CVE-2011-1576} - [net] rose: Add length checks to CALL_REQUEST parsing (Ben
          Hutchings) {CVE-2011-1493} - [net] rose_loopback_timer sets VC number &lt;=
          ROSE_DEFAULT_MAXVC (Bernard Pidoux F6BVP) {CVE-2011-1493}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:29.033-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:56.156-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:17.325-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27955 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:51.825-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:40.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132686"/>
            <criterion comment="ofa-2.6.32-300.4.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132445"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132912"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132773"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:133073"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132183"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:133049"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.4.1.el5uek" test_ref="oval:org.mitre.oval:tst:132946"/>
            <criterion comment="ofa-2.6.32-300.4.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132496"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132385"/>
            <criterion comment="mlnx_en-2.6.32-300.4.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132710"/>
            <criterion comment="ofa-2.6.32-300.4.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132812"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132548"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132412"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132956"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132270"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132835"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.4.1.el6uek" test_ref="oval:org.mitre.oval:tst:132824"/>
            <criterion comment="mlnx_en-2.6.32-300.4.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132906"/>
            <criterion comment="ofa-2.6.32-300.4.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133015"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27953" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0600 -- dovecot security and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0600.html" ref_id="ELSA-2011-0600"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3707" ref_id="CVE-2010-3707"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3780" ref_id="CVE-2010-3780"/>
        <description>[2.0.9-2]
- fix issues and assert crashes found in 2.0.9 (lmtp,dotlock,zlib)

[2.0.9-1]
- dovecot updated to 2.0.9
- fixed a high system CPU usage / high context switch count performance problem
- lda: Fixed a crash when trying to send 'out of quota' reply

[2.0.8-1]
- dovecot updated to 2.0.8 (fixes #654226), pigeonhole updated to 0.2.2
- IMAP: Fixed SELECT QRESYNC not to crash on mailbox close if a lot of changes w
ere being sent. 
- Fixed leaking fds when writing to dovecot.mailbox.log.
- Fixed rare dovecot.index.cache corruption
- zlib: Fixed several crashes, which mainly showed up with mbox.
- acl: Fixed crashing when sometimes listing shared mailboxes via dict proxy.
- mdbox: Fixed potential assert-crash when saving multiple messages
  in one transaction
- dsync: a lot of fixes
- fixed lda + sieve crash</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:39">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:44.861-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:55.725-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:17.024-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:39:44.826-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:39:44.826-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dovecot is earlier than 0:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:133810"/>
          <criterion comment="dovecot-devel is earlier than 0:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:133278"/>
          <criterion comment="dovecot-mysql is earlier than 0:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:133852"/>
          <criterion comment="dovecot-pgsql is earlier than 0:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:133855"/>
          <criterion comment="dovecot-pigeonhole is earlier than 0:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:133648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27951" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0862 -- nss security update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
          <product>nss-softokn</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0862.html" ref_id="ELSA-2010-0862"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3170" ref_id="CVE-2010-3170"/>
        <description>nss:

[3.12.8-1.0.1.el6]
- Update expired PayPalEE.cert to fix build failure
- Use blank image instead of clean.gif in nss-3.12.8-stripped.tar.bz2

[3.12.8-1]
- Update to 3.12.8

nss-softokn:

[3.12.8-1]
- Update to 3.12.8

nss-util:

[3.12.7-1]
- Update to 3.12.7</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:08.165-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:55.296-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:16.735-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:49:13.029-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:49:13.029-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nss is earlier than 0:3.12.8-1.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134100"/>
          <criterion comment="nss-softokn is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:134282"/>
          <criterion comment="nss-util is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:134139"/>
          <criterion comment="nss-devel is earlier than 0:3.12.8-1.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134335"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.8-1.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134367"/>
          <criterion comment="nss-softokn-devel is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:133590"/>
          <criterion comment="nss-softokn-freebl is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:133949"/>
          <criterion comment="nss-sysinit is earlier than 0:3.12.8-1.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134067"/>
          <criterion comment="nss-tools is earlier than 0:3.12.8-1.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134361"/>
          <criterion comment="nss-util-devel is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:134299"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27949" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-1003 -- git security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>git</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-1003.html" ref_id="ELSA-2010-1003"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3906" ref_id="CVE-2010-3906"/>
        <description>[1.7.1-2.1]
- fix CVE-2010-3906</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:52.642-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:54.858-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:16.325-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:16:55.401-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:16:55.401-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="git is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134664"/>
          <criterion comment="emacs-git is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134429"/>
          <criterion comment="emacs-git-el is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134226"/>
          <criterion comment="git-all is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134170"/>
          <criterion comment="git-cvs is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134627"/>
          <criterion comment="git-daemon is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134425"/>
          <criterion comment="git-email is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:133743"/>
          <criterion comment="git-gui is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134684"/>
          <criterion comment="git-svn is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134466"/>
          <criterion comment="gitk is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134516"/>
          <criterion comment="gitweb is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134683"/>
          <criterion comment="perl-Git is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134725"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27947" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1364 -- kdelibs security and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1364.html" ref_id="ELSA-2011-1364"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3365" ref_id="CVE-2011-3365"/>
        <description>[6:4.3.4-11.4]
- Resolves: bz#743951, use ca-certificates' ca-bundle.crt

[6:4.3.4-11.3]
- Resolves: bz#743515, CVE-2011-3365 - input validation failure</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:10.649-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:54.497-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:16.097-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kdelibs is earlier than 0:4.3.4-11.el6_1.4" test_ref="oval:org.mitre.oval:tst:133143"/>
          <criterion comment="kdelibs-apidocs is earlier than 0:4.3.4-11.el6_1.4" test_ref="oval:org.mitre.oval:tst:133114"/>
          <criterion comment="kdelibs-common is earlier than 0:4.3.4-11.el6_1.4" test_ref="oval:org.mitre.oval:tst:133107"/>
          <criterion comment="kdelibs-devel is earlier than 0:4.3.4-11.el6_1.4" test_ref="oval:org.mitre.oval:tst:132672"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27944" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0866 -- cups security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0866.html" ref_id="ELSA-2010-0866"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2941" ref_id="CVE-2010-2941"/>
        <description>[1:1.4.2-35:.1]
- Applied patch to fix cupsd memory corruption vulnerability
  (CVE-2010-2941, STR #3648, bug #624438).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:59.240-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:54.300-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:15.992-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:05:52.690-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:05:52.690-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups is earlier than 0:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:133936"/>
          <criterion comment="cups-devel is earlier than 0:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:134315"/>
          <criterion comment="cups-libs is earlier than 0:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:134259"/>
          <criterion comment="cups-lpd is earlier than 0:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:134364"/>
          <criterion comment="cups-php is earlier than 0:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:134198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27943" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0328 -- subversion security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0328.html" ref_id="ELSA-2011-0328"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0715" ref_id="CVE-2011-0715"/>
        <description>[1.6.11-2.3]
- add security fix for CVE-2011-0715 (#681173)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:06.125-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:54.104-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:15.885-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:00:49.566-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:00:49.566-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="subversion is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:134062"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:134201"/>
          <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:133699"/>
          <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:133986"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:134069"/>
          <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:133603"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:133869"/>
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:134224"/>
          <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:133615"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27942" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1749 -- libxml2 security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1749.html" ref_id="ELSA-2011-1749"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4008" ref_id="CVE-2010-4008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4494" ref_id="CVE-2010-4494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0216" ref_id="CVE-2011-0216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1944" ref_id="CVE-2011-1944"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2821" ref_id="CVE-2011-2821"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2834" ref_id="CVE-2011-2834"/>
        <description>[2.7.6-4.0.1.el6]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[2.7.6-4]
- Fixes another XPath problem CVE-2011-2834
- Resolves: rhbz#732335

[2.7.6-3]
- Fixes various other issues in 2.7.6 XPath evaluation
- Resolves: rhbz#732335

[2.7.6-2]
- Fix a potential crasher in XPath or XSLT, CVE-2011-1944
- Resolves: rhbz#710397</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:15.311-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:53.992-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:15.758-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libxml2 is earlier than 0:2.7.6-4.0.1.el6" test_ref="oval:org.mitre.oval:tst:133100"/>
          <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.0.1.el6" test_ref="oval:org.mitre.oval:tst:132999"/>
          <criterion comment="libxml2-python is earlier than 0:2.7.6-4.0.1.el6" test_ref="oval:org.mitre.oval:tst:132966"/>
          <criterion comment="libxml2-static is earlier than 0:2.7.6-4.0.1.el6" test_ref="oval:org.mitre.oval:tst:133027"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27939" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1241 -- ecryptfs-utils security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ecryptfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1241.html" ref_id="ELSA-2011-1241"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1831" ref_id="CVE-2011-1831"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1832" ref_id="CVE-2011-1832"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1834" ref_id="CVE-2011-1834"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1835" ref_id="CVE-2011-1835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1837" ref_id="CVE-2011-1837"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3145" ref_id="CVE-2011-3145"/>
        <description>[82-6.3]
- do not forget to set the group id in mount.ecryptfs_private

[82-6.2]
- fix regression in ecryptfs-setup-private

[82-6.1]
- security fixes:
- privilege escalation via mountpoint race conditions (CVE-2011-1831, CVE-2011-1832)
- race condition when checking source during mount (CVE-2011-1833)
- mtab corruption via improper handling (CVE-2011-1834)
- key poisoning via insecure temp directory handling (CVE-2011-1835)
- arbitrary file overwrite via lock counter race (CVE-2011-1837)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:43.558-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:53.407-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:15.468-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:47:19.039-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:47:19.039-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:133573"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:133220"/>
            <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:133195"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:133444"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:133412"/>
            <criterion comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:132832"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27936" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0052 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0052.html" ref_id="ELSA-2012-0052"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0056" ref_id="CVE-2012-0056"/>
        <description>[2.6.32-220.4.1.el6]
- [fs] Revert 'proc: enable writing to /proc/pid/mem' (Johannes Weiner) [782649 782650] {CVE-2012-0056}

[2.6.32-220.3.1.el6]
- [kernel] Remove 'WARNING: at kernel/sched.c:5915' (Larry Woodman) [768288 766051]
- [x86] kernel: Fix memory corruption in module load (Prarit Bhargava) [769595 767140]
- [kernel] Reset clocksource watchdog after sysrq-t (Prarit Bhargava) [755867 742890]
- [x86] AMD: Make tsc=reliable override boot time stability checks (Prarit Bhargava) [755867 742890]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:24.039-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:53.294-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:15.339-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:26:46.408-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:26:46.408-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:132668"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:131988"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:132463"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:132190"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:132783"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:132867"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:132830"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:132501"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:132736"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27928" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1581 -- ruby security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1581.html" ref_id="ELSA-2011-1581"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2705" ref_id="CVE-2011-2705"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3009" ref_id="CVE-2011-3009"/>
        <description>[1.8.7.352-3]
- mkconfig.rb: fix for continued lines.
  * ruby-1.8.7-p352-mkconfig.rb-fix-for-continued-lines.patch
- Resolves: rhbz#730287

[1.8.7.352-2]
- Fix of ruby interpreter crash in FIPS mode.
  * ruby-1.8.7-FIPS.patch
- Resolves: rhbz#717709

[1.8.7.352-1]
- Update to Ruby 1.8.7-p352.
  * Remove Patch43: ruby-1.8.7-CVE-2011-1004.patch; subsumed
  * Remove Patch44: ruby-1.8.7-CVE-2011-1005.patch; subsumed
  * Remove Patch200: ruby-1.8.7-webrick-CVE.patch; subsumed
- Resolves: rhbz#706332
- Fix of conflict between 32bit and 64bit library versions.
- Resolves: rhbz#674787
- Add systemtap static probes.
- Resolves: rhbz#673162
- Remove duplicate path entry
- Resolves: rhbz#722887

[1.8.7.299-8]
- Address CVE-2011-1004 'Symlink race condition by removing directory trees in
  fileutils module'
  * ruby-1.8.7-CVE-2011-1004.patch
- Address CVE-2011-1005 'Untrusted codes able to modify arbitrary strings'
  * ruby-1.8.7-CVE-2011-1005.patch
- Address CVE-2011-0188 'memory corruption in BigDecimal on 64bit platforms'
  * ruby-1.8.7-CVE-2011-0188.patch
- Resolves: rhbz#709964</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:19.920-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:52.188-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:14.780-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:133111"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:132681"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:133105"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:133033"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:132734"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:132943"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:132908"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:133103"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:132700"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27926" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0406 -- quagga security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0406.html" ref_id="ELSA-2011-0406"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1674" ref_id="CVE-2010-1674"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1675" ref_id="CVE-2010-1675"/>
        <description>[0.99.15-5_el6_0.2]
- Resolves: #684750 - CVE-2010-1674 CVE-2010-1675 quagga various flaws</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:53">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:42.076-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:51.622-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:14.499-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:52:06.635-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:52:06.635-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="quagga is earlier than 0:0.99.15-5.el6_0.2" test_ref="oval:org.mitre.oval:tst:134022"/>
          <criterion comment="quagga-contrib is earlier than 0:0.99.15-5.el6_0.2" test_ref="oval:org.mitre.oval:tst:133345"/>
          <criterion comment="quagga-devel is earlier than 0:0.99.15-5.el6_0.2" test_ref="oval:org.mitre.oval:tst:134101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27922" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0135 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0135.html" ref_id="ELSA-2012-0135"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3563" ref_id="CVE-2011-3563"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0497" ref_id="CVE-2012-0497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0501" ref_id="CVE-2012-0501"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0502" ref_id="CVE-2012-0502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0503" ref_id="CVE-2012-0503"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0505" ref_id="CVE-2012-0505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0506" ref_id="CVE-2012-0506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3571" ref_id="CVE-2011-3571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5035" ref_id="CVE-2011-5035"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0507" ref_id="CVE-2012-0507"/>
        <description>[1:1.6.0.0-1.43.1.10.6]
- Updated to IcedTea6 1.10.6
- Resolves: rhbz#787144
- Security fixes
  - S7082299: Fix in AtomicReferenceArray
  - S7088367: Fix issues in java sound
  - S7110683: Issues with some KeyboardFocusManager method
  - S7110687: Issues with TimeZone class
  - S7110700: Enhance exception throwing mechanism in ObjectStreamClass
  - S7110704: Issues with some method in corba
  - S7112642: Incorrect checking for graphics rendering object
  - S7118283: Better input parameter checking in zip file processing
  - S7126960: Add property to limit number of request headers to the HTTP Server
- Bug fixes
  - RH580478: Desktop files should not use hardcoded path
- Removed upstreamed patch7 - java-1.6.0-openjdk-6_2-Z-rmi-fix.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:18.722-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:51.282-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:14.246-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:04:11.677-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:04:11.677-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:132640"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:132754"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:132679"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:132711"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:132747"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27919" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0390 -- rsync security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>rsync</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0390.html" ref_id="ELSA-2011-0390"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1097" ref_id="CVE-2011-1097"/>
        <description>[3.0.6-5.1]
- Add upstream patch to fix CVE-2011-1097 - Incremental file-list
  corruption due to temporary file_extra_cnt increments
  Resolves: #684932</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:45.433-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:50.849-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:14.041-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:16:14.257-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:16:14.257-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="rsync is earlier than 0:3.0.6-5.el6_0.1" test_ref="oval:org.mitre.oval:tst:133386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27917" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0856 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0856.html" ref_id="ELSA-2011-0856"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0862" ref_id="CVE-2011-0862"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0864" ref_id="CVE-2011-0864"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0865" ref_id="CVE-2011-0865"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0867" ref_id="CVE-2011-0867"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0868" ref_id="CVE-2011-0868"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0869" ref_id="CVE-2011-0869"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0871" ref_id="CVE-2011-0871"/>
        <description>[1.6.0.0-1.39.1.9.8]
- Resolves: rhbz#709375
- Bumped to IcedTea6 1.9.8
- Copy fontconfig files to match names for current and next release
- RH706250, S6213702, CVE-2011-0872: (so) non-blocking sockets with TCP urgent
  disabled get still selected for read ops (win)
- RH706106, S6618658, CVE-2011-0865: Vulnerability in deserialization
- RH706111, S7012520, CVE-2011-0815: Heap overflow vulnerability in
  FileDialog.show()
- RH706139, S7013519, CVE-2011-0822, CVE-2011-0862: Integer overflows in 2D
  code
- RH706153, S7013969, CVE-2011-0867: NetworkInterface.toString can reveal
  bindings
- RH706234, S7013971, CVE-2011-0869: Vulnerability in SAAJ
- RH706239, S7016340, CVE-2011-0870: Vulnerability in SAAJ
- RH706241, S7016495, CVE-2011-0868: Crash in Java 2D transforming an image
  with scale close to zero
- RH706248, S7020198, CVE-2011-0871: ImageIcon creates Component with null acc
- RH706245, S7020373, CVE-2011-0864: JSR rewriting can overflow memory address
  size variables</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:20.420-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:49.986-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:13.638-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:57:11.879-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:57:11.879-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:133787"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:133504"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:133683"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:133467"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:133645"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27916" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2037 -- Unbreakable Enterprise kernel security and bug fix update
          (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2037.html" ref_id="ELSA-2011-2037"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1020" ref_id="CVE-2011-1020"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1577" ref_id="CVE-2011-1577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1585" ref_id="CVE-2011-1585"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2495" ref_id="CVE-2011-2495"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2525" ref_id="CVE-2011-2525"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3638" ref_id="CVE-2011-3638"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4110" ref_id="CVE-2011-4110"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4330" ref_id="CVE-2011-4330"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2707" ref_id="CVE-2011-2707"/>
        <description>[2.6.32-300.3.1.el6uek] - proc: fix oops on invalid /proc/&lt;pid>/maps
          access (Linux Torvalds) - Revert 'capabilities: do not grant full privs for setuid w/ file
          caps + no effective caps' (Joe Jin) - [mm]: Use MMF_COMPAT instead ia32_compat to prevent
          kabi be broken (Joe Jin) - proc: enable writing to /proc/pid/mem (Stephen Wilson) - proc:
          make check_mem_permission() return an mm_struct on success (Stephen Wilson) - proc: hold
          cred_guard_mutex in check_mem_permission() (Joe Jin) - proc: disable mem_write after exec
          (Stephen Wilson) - mm: implement access_remote_vm (Stephen Wilson) - mm: factor out main
          logic of access_process_vm (Stephen Wilson) - mm: use mm_struct to resolve gate vma's in
          __get_user_pages (Stephen Wilson) - mm: arch: rename in_gate_area_no_task to
          in_gate_area_no_mm (Stephen Wilson) - mm: arch: make in_gate_area take an mm_struct
          instead of a task_struct (Stephen Wilson) - mm: arch: make get_gate_vma take an mm_struct
          instead of a task_struct (Stephen Wilson) - x86: mark associated mm when running a task in
          32 bit compatibility mode (Stephen Wilson) - x86: add context tag to mark mm when running
          a task in 32-bit compatibility mode (Stephen Wilson) - auxv: require the target to be
          tracable (or yourself) (Al Viro) - close race in /proc/*/environ (Al Viro) - report errors
          in /proc/*/*map* sanely (Al Viro) - pagemap: close races with suid execve (Al Viro) - make
          sessionid permissions in /proc/*/task/* match those in /proc/* (Al Viro) - Revert 'report
          errors in /proc/*/*map* sanely' (Joe Jin) - Revert 'proc: fix oops on invalid
          /proc/&lt;pid>/maps access' (Joe Jin)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:13.623-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:49.641-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:13.435-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:132958 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:54.289-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:39.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132869"/>
            <criterion comment="ofa-2.6.32-300.3.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132938"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132368"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:133054"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132935"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132947"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132175"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.3.1.el5uek" test_ref="oval:org.mitre.oval:tst:132973"/>
            <criterion comment="ofa-2.6.32-300.3.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132756"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132929"/>
            <criterion comment="ofa-2.6.32-300.3.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132557"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132408"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132978"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:133116"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132891"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:133094"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.3.1.el6uek" test_ref="oval:org.mitre.oval:tst:132936"/>
            <criterion comment="ofa-2.6.32-300.3.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132958"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27915" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3106 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3106.html" ref_id="ELSA-2014-3106"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5471" ref_id="CVE-2014-5471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5472" ref_id="CVE-2014-5472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9090" ref_id="CVE-2014-9090"/>
        <description>kernel-uek [3.8.13-55.1.2.el6uek] - isofs: Fix unbounded recursion when
          processing relocated directories (Jan Kara) [Orabug: 20224059] {CVE-2014-5471}
          {CVE-2014-5472} - x86_64, traps: Stop using IST for #SS (Andy Lutomirski) [Orabug:
          20224027] {CVE-2014-9090} {CVE-2014-9322}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:32.335-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:12.595-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:06.661-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37983 - Corrected package names in objects and versions in states." date="2015-02-26T20:03:00.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T20:05:55.304-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:39.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dtrace-modules-3.8.13-55.1.2.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:136714"/>
            <criterion comment="kernel-uek is earlier than 0:3.8.13-55.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:135970"/>
            <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-55.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:136752"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-55.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:136808"/>
            <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-55.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:136933"/>
            <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-55.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:136959"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-55.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:136897"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dtrace-modules-3.8.13-55.1.2.el7uek is earlier than 0:0.4.3-4.el7" test_ref="oval:org.mitre.oval:tst:136954"/>
            <criterion comment="kernel-uek is earlier than 0:3.8.13-55.1.2.el7uek" test_ref="oval:org.mitre.oval:tst:136795"/>
            <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-55.1.2.el7uek" test_ref="oval:org.mitre.oval:tst:136547"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-55.1.2.el7uek" test_ref="oval:org.mitre.oval:tst:136826"/>
            <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-55.1.2.el7uek" test_ref="oval:org.mitre.oval:tst:136794"/>
            <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-55.1.2.el7uek" test_ref="oval:org.mitre.oval:tst:136946"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-55.1.2.el7uek" test_ref="oval:org.mitre.oval:tst:136651"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27914" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2003 -- Unbreakable Enterprise kernel security and bug fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2003.html" ref_id="ELSA-2012-2003"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4081" ref_id="CVE-2011-4081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4347" ref_id="CVE-2011-4347"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0038" ref_id="CVE-2012-0038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0045" ref_id="CVE-2012-0045"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0207" ref_id="CVE-2012-0207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4077" ref_id="CVE-2011-4077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4132" ref_id="CVE-2011-4132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4622" ref_id="CVE-2011-4622"/>
        <description>[2.6.32-300.11.1.el6uek] - [fs] xfs: Fix possible memory corruption in
          xfs_readlink (Carlos Maiolino) {CVE-2011-4077} - [scsi] increase qla2xxx firmware ready
          time-out (Joe Jin) - [scsi] qla2xxx: Module parameter to control use of async or sync port
          login (Joe Jin) - [net] tg3: Fix single-vector MSI-X code (Joe Jin) - [net] qlge: fix size
          of external list for TX address descriptors (Joe Jin) - [net] e1000e: Avoid wrong check on
          TX hang (Joe Jin) - crypto: ghash - Avoid null pointer dereference if no key is set (Nick
          Bowler) {CVE-2011-4081} - jbd/jbd2: validate sb->s_first in journal_get_superblock()
          (Eryu Guan) {CVE-2011-4132} - KVM: Device assignment permission checks (Joe Jin)
          {CVE-2011-4347} - KVM: x86: Prevent starting PIT timers in the absence of irqchip support
          (Jan Kiszka) {CVE-2011-4622} - xfs: validate acl count (Joe Jin) {CVE-2012-0038} - KVM:
          x86: fix missing checks in syscall emulation (Joe Jin) {CVE-2012-0045} - KVM: x86: extend
          'struct x86_emulate_ops' with 'get_cpuid' (Joe Jin) {CVE-2012-0045} - igmp: Avoid zero
          delay when receiving odd mixture of IGMP queries (Ben Hutchings) {CVE-2012-0207} - ipv4:
          correct IGMP behavior on v3 query during v2-compatibility mode (David Stevens) - fuse: fix
          fuse request unique id (Srinivas Eeda) [orabug 13816349]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:11.239-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:49.386-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:13.281-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:132608 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:40.164-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:38.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:131662"/>
            <criterion comment="mlnx_en-2.6.32-300.11.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132631"/>
            <criterion comment="ofa-2.6.32-300.11.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132480"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132578"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132545"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132476"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132162"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:131840"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.11.1.el5uek" test_ref="oval:org.mitre.oval:tst:132335"/>
            <criterion comment="mlnx_en-2.6.32-300.11.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132588"/>
            <criterion comment="ofa-2.6.32-300.11.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132608"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132180"/>
            <criterion comment="mlnx_en-2.6.32-300.11.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132657"/>
            <criterion comment="ofa-2.6.32-300.11.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132274"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:131957"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132488"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132303"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132540"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:132499"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.11.1.el6uek" test_ref="oval:org.mitre.oval:tst:131751"/>
            <criterion comment="mlnx_en-2.6.32-300.11.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131729"/>
            <criterion comment="ofa-2.6.32-300.11.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132280"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27906" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1356 -- openswan security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1356.html" ref_id="ELSA-2011-1356"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3380" ref_id="CVE-2011-3380"/>
        <description>[2.6.32-4.2]
Resolves: #742069 CVE-2011-3380</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:22.888-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:48.682-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:12.858-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:24:27.462-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:24:27.462-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.2" test_ref="oval:org.mitre.oval:tst:133379"/>
          <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.2" test_ref="oval:org.mitre.oval:tst:133062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27904" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0616 -- pidgin security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0616.html" ref_id="ELSA-2011-0616"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1091" ref_id="CVE-2011-1091"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4922" ref_id="CVE-2011-4922"/>
        <description>[2.7.9-3.el6]
- Add patch for RH bug #684685 (zero-out crypto keys before freeing).

[2.7.9-2.el6]
- Add patch for CVE-2011-1091 (RH bug #683031).

[2.7.9-1.el6]
- Update to 2.7.9 (RH bug #616917).
- Remove patches now included upstream:
    pidgin-2.6.6-clientLogin-proxy-fix.patch
    pidgin-2.6.6-clientLogin-use-https.patch
    pidgin-2.6.6-CVE-2010-1624.patch
    pidgin-2.6.6-CVE-2010-3711.patch
- Disable the translation updates patch.  It doesn't apply anymore and
  will have to be redone.  Saving the patch for now in case some parts
  are still useful to translators.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:07.581-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:48.321-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:12.634-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:23:49.765-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:23:49.765-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pidgin is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:133851"/>
          <criterion comment="finch is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:133928"/>
          <criterion comment="finch-devel is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:134070"/>
          <criterion comment="libpurple is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:133976"/>
          <criterion comment="libpurple-devel is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:133658"/>
          <criterion comment="libpurple-perl is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:133861"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:133733"/>
          <criterion comment="pidgin-devel is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:134030"/>
          <criterion comment="pidgin-docs is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:133083"/>
          <criterion comment="pidgin-perl is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:133985"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27903" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2021 -- Oracle Linux 6 Unbreakable Enterprise kernel security fix update
          (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2021.html" ref_id="ELSA-2011-2021"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1767" ref_id="CVE-2011-1767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1768" ref_id="CVE-2011-1768"/>
        <description>[2.6.32-100.37.1.el6uek] - [net] gre: fix netns vs proto registration ordering
          {CVE-2011-1767} - [net] tunnels: fix netns vs proto registration ordering
          {CVE-2011-1768}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:28.656-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:48.099-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:12.466-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36745 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:36.347-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:37.646-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133249"/>
            <criterion comment="ofa-2.6.32-100.37.1.el5uek is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133130"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133665"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133704"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:132744"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133685"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133090"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:133425"/>
            <criterion comment="ofa-2.6.32-100.37.1.el5uekdebug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133548"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133452"/>
            <criterion comment="ofa-2.6.32-100.37.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133638"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:132843"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133300"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133720"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133740"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133586"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:133651"/>
            <criterion comment="ofa-2.6.32-100.37.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133524"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27898" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0058 -- glibc security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0058.html" ref_id="ELSA-2012-0058"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5029" ref_id="CVE-2009-5029"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4609" ref_id="CVE-2011-4609"/>
        <description>[2.12-1.47.el6_2.5]
- Avoid high cpu usage when accept fails with EMFILE (#767692)

[2.12-1.47.el6_2.4]
- Make implementation of ARENAS_TEST and ARENAS_MAX match
  documentation (#769594)
- Check malloc arena atomically  (#769594)

[2.12-1.47.el6_2.3]
- Check values from TZ file header (#767692)

[2.12-1.47.el6_2.2]
- Correctly reparse group line after enlarging the buffer
  (#766484)

[2.12-1.47.el6_2.1]
- Fix grouping and reuse other locales in various locales (#754116)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:19.246-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:46.248-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:11.665-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:16:29.542-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:16:29.542-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:132693"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:132750"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:132811"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:132451"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:132570"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:132198"/>
          <criterion comment="nscd is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:132833"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27894" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0128 -- httpd security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0128.html" ref_id="ELSA-2012-0128"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3607" ref_id="CVE-2011-3607"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3639" ref_id="CVE-2011-3639"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4317" ref_id="CVE-2011-4317"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0031" ref_id="CVE-2012-0031"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0053" ref_id="CVE-2012-0053"/>
        <description>[2.2.15-15.0.1.el6_2.1]
- replace index.html with Oracle's index page oracle_index.html
  update vstring in specfile

[2.2.15-15.1]
- add security fixes for CVE-2011-4317, CVE-2012-0053, CVE-2012-0031,
  CVE-2011-3607 (#787598)
- obviates fix for CVE-2011-3638, patch removed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:21.398-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:45.762-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:11.433-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:05:34.915-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:05:34.915-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="httpd is earlier than 0:2.2.15-15.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132755"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.15-15.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132704"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.15-15.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132055"/>
          <criterion comment="httpd-tools is earlier than 0:2.2.15-15.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132550"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.15-15.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27893" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0369 -- wireshark security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0369.html" ref_id="ELSA-2011-0369"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0444" ref_id="CVE-2011-0444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0538" ref_id="CVE-2011-0538"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0713" ref_id="CVE-2011-0713"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1139" ref_id="CVE-2011-1139"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1140" ref_id="CVE-2011-1140"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1141" ref_id="CVE-2011-1141"/>
        <description>[1.2.15-1.0.1.el6_0.1]
- Add oracle-ocfs2-network.patch to allow disassembly of OCFS2 interconnect

[1.2.15-1]
- upgrade to 1.2.15
- see http://www.wireshark.org/docs/relnotes/wireshark-1.2.14.html
- see http://www.wireshark.org/docs/relnotes/wireshark-1.2.15.html
- Resolves: CVE-2011-0444 CVE-2011-0538 CVE-2011-0713 CVE-2011-1139
  CVE-2011-1140 CVE-2011-1141 CVE-2011-1143</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:44.620-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:45.121-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:11.147-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:16:05.483-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:16:05.483-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="wireshark is earlier than 0:1.2.15-1.0.1.el6_0.1" test_ref="oval:org.mitre.oval:tst:133246"/>
          <criterion comment="wireshark-devel is earlier than 0:1.2.15-1.0.1.el6_0.1" test_ref="oval:org.mitre.oval:tst:133776"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.2.15-1.0.1.el6_0.1" test_ref="oval:org.mitre.oval:tst:133808"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27890" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0516 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0516.html" ref_id="ELSA-2012-0516"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0467" ref_id="CVE-2012-0467"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0468" ref_id="CVE-2012-0468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0469" ref_id="CVE-2012-0469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0470" ref_id="CVE-2012-0470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0471" ref_id="CVE-2012-0471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0472" ref_id="CVE-2012-0472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0473" ref_id="CVE-2012-0473"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0474" ref_id="CVE-2012-0474"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0477" ref_id="CVE-2012-0477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0478" ref_id="CVE-2012-0478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0479" ref_id="CVE-2012-0479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3062" ref_id="CVE-2011-3062"/>
        <description>[10.0.4-1.0.1.el6_2]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[10.0.4-1]
- Update to 10.0.4 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:08.574-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:44.477-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:10.735-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:43:20.417-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:43:20.417-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:10.0.4-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131519"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27888" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0880 -- qt security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0880.html" ref_id="ELSA-2012-0880"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5076" ref_id="CVE-2010-5076"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3922" ref_id="CVE-2011-3922"/>
        <description>[1:4.6.2-24]
- Resolves: bz#734444, list of trusted CA certificates should not be compiled into library

[1:4.6.2-23]
- Resolves: bz#805433, CVE-2011-3922

[1:4.6.2-22]
- Resolves: bz#694684, phonon crash

[1:4.6.2-21]
- Resolves: #rhbz757793, add OpenGL 3.1, 3.2, 3.3 and 4.0 recognition to QGLFormat</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:18.196-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:43.171-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:10.337-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:57:54.225-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:57:54.225-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qt is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131521"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131467"/>
          <criterion comment="qt-demos is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131507"/>
          <criterion comment="qt-devel is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131779"/>
          <criterion comment="qt-doc is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131619"/>
          <criterion comment="qt-examples is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131539"/>
          <criterion comment="qt-mysql is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131691"/>
          <criterion comment="qt-odbc is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131801"/>
          <criterion comment="qt-postgresql is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131669"/>
          <criterion comment="qt-sqlite is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131504"/>
          <criterion comment="qt-x11 is earlier than 0:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:131722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27887" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0859 -- poppler security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>poppler</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0859.html" ref_id="ELSA-2010-0859"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3702" ref_id="CVE-2010-3702"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3703" ref_id="CVE-2010-3703"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3704" ref_id="CVE-2010-3704"/>
        <description>[0.12.4-3.el6.1]
- Add poppler-0.12.4-CVE-2010-3702.patch
    (Properly initialize parser)
- Add poppler-0.12.4-CVE-2010-3703.patch
    (Properly initialize stack)
- Add poppler-0.12.4-CVE-2010-3704.patch
    (Fix crash in broken pdf (code &lt; 0))
- Resolves: #639859</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:02.349-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:42.950-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:10.225-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:41:52.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:41:52.567-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="poppler is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134140"/>
          <criterion comment="poppler-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134125"/>
          <criterion comment="poppler-glib is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134207"/>
          <criterion comment="poppler-glib-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134440"/>
          <criterion comment="poppler-qt is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134266"/>
          <criterion comment="poppler-qt-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134452"/>
          <criterion comment="poppler-qt4 is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134079"/>
          <criterion comment="poppler-qt4-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134250"/>
          <criterion comment="poppler-utils is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134366"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27886" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1691 -- util-linux-ng security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>util-linux-ng</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1691.html" ref_id="ELSA-2011-1691"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1675" ref_id="CVE-2011-1675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1677" ref_id="CVE-2011-1677"/>
        <description>[2.17.2-12.4]
- fix CVE-2011-1675 - mount fails to anticipate RLIMIT_FSIZE
- fix CVE-2011-1677 - umount may fail to remove /etc/mtab~ lock file

[2.17.2-12.3]
- fix fatal typos in patch for #723546

[2.17.2-12.2]
- rename /etc/hushlogin to /etc/hushlogins (#696731)

[2.17.2-12.1]
- fix #723546 - Defects revealed by Coverity scan
- fix #723352 - cfdisk cannot read default installer partitioning
- fix #712158 - uid/gid overflow in ipcs
- fix #696959 - wipefs(8) reject partitioned devices
- fix #694648 - document blank line at head of fstab
- fix #684203 - umount fails on inconsistent fstab
- fix #679831 --lines does not work
- fix #679741 - canonicalize swap device
- fix #692119 - include fstrim tool
- fix #675999 - blkid crashes on a server with more than 128 storage devices
- fix #696731 - display failed login attempts
- fix #726092 - Pass host name from agetty to login
- fix #716995 - Remove Deprecation Statement in /etc/udev/rules.d/60-raw.rules
- fix #712808 - uuidd should depend on chkconfig
- fix #723638 - Backport upstream extensions for lsblk (RHEL6.2)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:30.992-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:42.837-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:10.144-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="util-linux-ng is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:132653"/>
          <criterion comment="libblkid is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:133095"/>
          <criterion comment="libblkid-devel is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:132797"/>
          <criterion comment="libuuid is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:132954"/>
          <criterion comment="libuuid-devel is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:132337"/>
          <criterion comment="uuidd is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:133078"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27885" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1141 -- dhcp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1141.html" ref_id="ELSA-2012-1141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3954" ref_id="CVE-2012-3954"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3571" ref_id="CVE-2012-3571"/>
        <description>[12:4.1.1-31.P1.0.1.el6_3.1]
- Added oracle-errwarn-message.patch

[12:4.1.1-31.P1.1]
- An error in the handling of malformed client identifiers can
  cause a denial-of-service condition in affected servers. (CVE-2012-3571, #843120)
- Memory Leaks Found In ISC DHCP (CVE-2012-3954, #843120)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:24.017-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:42.614-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:10.031-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:25:50.583-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:25:50.583-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dhcp is earlier than 0:4.1.1-31.P1.0.1.el6_3.1" test_ref="oval:org.mitre.oval:tst:131092"/>
          <criterion comment="dhclient is earlier than 0:4.1.1-31.P1.0.1.el6_3.1" test_ref="oval:org.mitre.oval:tst:131413"/>
          <criterion comment="dhcp-common is earlier than 0:4.1.1-31.P1.0.1.el6_3.1" test_ref="oval:org.mitre.oval:tst:131432"/>
          <criterion comment="dhcp-devel is earlier than 0:4.1.1-31.P1.0.1.el6_3.1" test_ref="oval:org.mitre.oval:tst:131393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27884" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0464 -- kdelibs security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0464.html" ref_id="ELSA-2011-0464"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1094" ref_id="CVE-2011-1094"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1168" ref_id="CVE-2011-1168"/>
        <description>[6:4.3.4-11.2]
- rebase the fix for CVE-2011-1094

[6:4.3.4-11.1]
- fixes CVE-2011-1094, CVE-2011-1168</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:58.047-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:42.292-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:09.898-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:11:10.273-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:11:10.273-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kdelibs is earlier than 0:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:133604"/>
          <criterion comment="kdelibs-apidocs is earlier than 0:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:133962"/>
          <criterion comment="kdelibs-common is earlier than 0:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:134006"/>
          <criterion comment="kdelibs-devel is earlier than 0:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:134020"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27880" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1741 -- php-pear security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php-pear</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1741.html" ref_id="ELSA-2011-1741"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1072" ref_id="CVE-2011-1072"/>
        <description>[1.9.4-4]
- fix patch application for #747361

[1.9.4-3]
- ignore REST cache creation failures as non-root user (#747361)

[1.9.4-2]
- fix XML-Util provides

[1.9.4-1]
- update to 1.9.4 (#651897)
- update XML_RPC to 1.5.4, Structures_Graph to 1.0.4, Archive_Tar to 1.3.7

[1.9.1-1]
- update to 1.9.1 (#651897)
- fix installation of XML_RPC license file</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:30.281-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:41.683-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:09.495-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="php-pear is earlier than 0:1.9.4-4.el6" test_ref="oval:org.mitre.oval:tst:132981"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27876" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1116 -- perl-DBD-Pg security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>perl-DBD-Pg</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1116.html" ref_id="ELSA-2012-1116"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1151" ref_id="CVE-2012-1151"/>
        <description>[2.15.1-4]
- Resolves: rhbz#841131 (CVE-2012-1151)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:21.659-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:41.182-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:09.150-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:50:26.375-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:50:26.375-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="perl-DBD-Pg is earlier than 0:1.49-4.el5_8" test_ref="oval:org.mitre.oval:tst:131473"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="perl-DBD-Pg is earlier than 0:2.15.1-4.el6_3" test_ref="oval:org.mitre.oval:tst:130574"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27873" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0324 -- libxml2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0324.html" ref_id="ELSA-2012-0324"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0841" ref_id="CVE-2012-0841"/>
        <description>[2.7.6-4.0.1.el6_2.4]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[2.7.6-4.el6_2.4]
- remove chunk in patch related to configure.in as it breaks rebuild
- Resolves: rhbz#788845

[2.7.6-4.el6_2.3]
- fix previous build to force compilation of randomization code
- Resolves: rhbz#788845

[2.7.6-4.el6_2.2]
- adds randomization to hash and dict structures CVE-2012-0841
- Resolves: rhbz#788845</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:27.024-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:40.539-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:08.781-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:00:38.346-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:00:38.346-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.0.1.el5_8.2" test_ref="oval:org.mitre.oval:tst:132330"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.0.1.el5_8.2" test_ref="oval:org.mitre.oval:tst:132615"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.0.1.el5_8.2" test_ref="oval:org.mitre.oval:tst:132464"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.7.6-4.0.1.el6_2.4" test_ref="oval:org.mitre.oval:tst:132614"/>
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.0.1.el6_2.4" test_ref="oval:org.mitre.oval:tst:132725"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-4.0.1.el6_2.4" test_ref="oval:org.mitre.oval:tst:132717"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-4.0.1.el6_2.4" test_ref="oval:org.mitre.oval:tst:132629"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27871" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0050 -- qemu-kvm security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0050.html" ref_id="ELSA-2012-0050"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0029" ref_id="CVE-2012-0029"/>
        <description>[qemu-kvm-0.12.1.2-2.209.el6_2.4]
- kvm-e1000-prevent-buffer-overflow-when-processing-legacy.patch [bz#772081]
- Resolves: bz#772081
  (EMBARGOED CVE-2012-0029 qemu-kvm: e1000: process_tx_desc legacy mode packets heap overflow [rhel-6.2.z])

[qemu-kvm-0.12.1.2-2.209.el6_2.3]
- kvm-Revert-virtio-blk-refuse-SG_IO-requests-with-scsi-of.patch [for bz#767721]
- kvm-virtio-blk-refuse-SG_IO-requests-with-scsi-off-v2.patch [bz#767721]
- CVE: CVE-2011-4127
- Resolves: bz#767721
  (qemu-kvm: virtio-blk: refuse SG_IO requests with scsi=off (CVE-2011-4127 mitigation) [rhel-6.2.z])

[qemu-kvm-0.12.1.2-2.209.el6_2.2]
- kvm-virtio-blk-refuse-SG_IO-requests-with-scsi-off.patch [bz#752375]
- CVE: CVE-2011-4127
- Resolves: bz#767721
  (EMBARGOED qemu-kvm: virtio-blk: refuse SG_IO requests with scsi=off (CVE-2011-4127 mitigation) [rhel-6.3])
- Resolves: bz#767906
  (qemu-kvm should be built with full relro and PIE support)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:09.076-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:40.255-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:08.613-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:03:04.255-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:03:04.255-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.209.el6_2.4" test_ref="oval:org.mitre.oval:tst:132848"/>
          <criterion comment="qemu-img is earlier than 0:0.12.1.2-2.209.el6_2.4" test_ref="oval:org.mitre.oval:tst:132761"/>
          <criterion comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.209.el6_2.4" test_ref="oval:org.mitre.oval:tst:132849"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27869" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1247 -- rsyslog security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>rsyslog</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1247.html" ref_id="ELSA-2011-1247"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3200" ref_id="CVE-2011-3200"/>
        <description>[4.6.2-3.el6_1.2]
- add patch to resolve buffer overflow (CVE-2011-3200)
  Resolves: #733647</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:47.294-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:40.048-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:08.523-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:32:35.822-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:32:35.822-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="rsyslog is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:133566"/>
          <criterion comment="rsyslog-gnutls is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:133422"/>
          <criterion comment="rsyslog-gssapi is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:133271"/>
          <criterion comment="rsyslog-mysql is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:133568"/>
          <criterion comment="rsyslog-pgsql is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:133397"/>
          <criterion comment="rsyslog-relp is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:132975"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27868" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0311 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0311.html" ref_id="ELSA-2011-0311"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1585" ref_id="CVE-2010-1585"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0053" ref_id="CVE-2011-0053"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0061" ref_id="CVE-2011-0061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0062" ref_id="CVE-2011-0062"/>
        <description>[3.1.8-4.0.2.el6_0]
- Replace clean.gif in tarball

[3.1.8-4.0.1.el6_0]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[3.1.8-4]
- Update to build3

[3.1.8-3]
- Update to build2

[3.1.8-2]
- Update to 3.1.8</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:09.372-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:39.681-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:08.389-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:53:10.148-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:53:10.148-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:3.1.8-4.0.2.el6_0" test_ref="oval:org.mitre.oval:tst:133687"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27866" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0586 -- libguestfs security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libguestfs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0586.html" ref_id="ELSA-2011-0586"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3851" ref_id="CVE-2010-3851"/>
        <description>[1.7.17-17]
- Remove dependency on gfs2-utils.
  resolves: rhbz#695138</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:26.930-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:39.458-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:08.266-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:42:52.021-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:42:52.021-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libguestfs is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133718"/>
          <criterion comment="guestfish is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133701"/>
          <criterion comment="libguestfs-devel is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133925"/>
          <criterion comment="libguestfs-java is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133864"/>
          <criterion comment="libguestfs-java-devel is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133887"/>
          <criterion comment="libguestfs-javadoc is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133895"/>
          <criterion comment="libguestfs-mount is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133917"/>
          <criterion comment="libguestfs-tools is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133911"/>
          <criterion comment="libguestfs-tools-c is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133437"/>
          <criterion comment="ocaml-libguestfs is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133774"/>
          <criterion comment="ocaml-libguestfs-devel is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133479"/>
          <criterion comment="perl-Sys-Guestfs is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133888"/>
          <criterion comment="python-libguestfs is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133754"/>
          <criterion comment="ruby-libguestfs is earlier than 0:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:133635"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27864" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0715 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0715.html" ref_id="ELSA-2012-0715"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3101" ref_id="CVE-2011-3101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1937" ref_id="CVE-2012-1937"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1938" ref_id="CVE-2012-1938"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1939" ref_id="CVE-2012-1939"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1940" ref_id="CVE-2012-1940"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1941" ref_id="CVE-2012-1941"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1944" ref_id="CVE-2012-1944"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1945" ref_id="CVE-2012-1945"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1946" ref_id="CVE-2012-1946"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1947" ref_id="CVE-2012-1947"/>
        <description>[10.0.5-2.0.1.el6_2]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[10.0.5-2]
- Update to 10.0.5 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:14.274-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:38.148-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:07.741-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:10:43.201-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:10:43.201-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:10.0.5-2.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131465"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27863" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1088 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1088.html" ref_id="ELSA-2012-1088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1948" ref_id="CVE-2012-1948"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1950" ref_id="CVE-2012-1950"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1951" ref_id="CVE-2012-1951"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1952" ref_id="CVE-2012-1952"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1953" ref_id="CVE-2012-1953"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1954" ref_id="CVE-2012-1954"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1955" ref_id="CVE-2012-1955"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1957" ref_id="CVE-2012-1957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1958" ref_id="CVE-2012-1958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1959" ref_id="CVE-2012-1959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1961" ref_id="CVE-2012-1961"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1962" ref_id="CVE-2012-1962"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1963" ref_id="CVE-2012-1963"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1964" ref_id="CVE-2012-1964"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1965" ref_id="CVE-2012-1965"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1966" ref_id="CVE-2012-1966"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1967" ref_id="CVE-2012-1967"/>
        <description>firefox
[10.0.6-1.0.1.el6_3]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.6-1]
- Update to 10.0.6 ESR

[10.0.5-3]
- Enabled WebM

[10.0.5-2]
- Added fix for mozbz#703633, rhbz#818341

xulrunner
[10.0.6-1.0.1.el6_3]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.6-1]
- Update to 10.0.6 ESR

[10.0.5-3]
- Added fix for rhbz#808136 (mozbz#762301)

[10.0.5-2]
- Enabled WebM (rhbz#798880)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:30.485-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:36.257-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:07.191-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:17:27.747-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:17:27.747-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.6-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131483"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131597"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130662"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.6-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131528"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130967"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131647"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27859" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1819 -- dhcp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1819.html" ref_id="ELSA-2011-1819"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4539" ref_id="CVE-2011-4539"/>
        <description>[12:4.1.1-25.P1.1]
- DoS due to processing certain regular expressions (CVE-2011-4539, #765682)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:19.581-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:35.914-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:07.027-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:07:27.185-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:07:27.185-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dhcp is earlier than 0:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132117"/>
          <criterion comment="dhclient is earlier than 0:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132300"/>
          <criterion comment="dhcp-common is earlier than 0:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132708"/>
          <criterion comment="dhcp-devel is earlier than 0:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132991"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27858" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0813 -- 389-ds-base security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0813.html" ref_id="ELSA-2012-0813"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0833" ref_id="CVE-2012-0833"/>
        <description>[1.2.10.2-15]
- Resolves: Bug 824014 - DS Shuts down intermittently</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:28.980-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:35.729-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:06.947-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:15:07.253-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:15:07.253-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="389-ds-base is earlier than 0:1.2.10.2-15.el6" test_ref="oval:org.mitre.oval:tst:131817"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.10.2-15.el6" test_ref="oval:org.mitre.oval:tst:131702"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.10.2-15.el6" test_ref="oval:org.mitre.oval:tst:131828"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27857" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1054 -- libtiff security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1054.html" ref_id="ELSA-2012-1054"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2088" ref_id="CVE-2012-2088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2113" ref_id="CVE-2012-2113"/>
        <description>[3.9.4-6]
- Add fixes for CVE-2012-2088, CVE-2012-2113
Resolves: #835748</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:26.716-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:35.463-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:06.794-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:23:54.056-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:23:54.056-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:131366"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:131428"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:131592"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:131209"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:130780"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27856" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0350 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0350.html" ref_id="ELSA-2012-0350"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4081" ref_id="CVE-2011-4081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4347" ref_id="CVE-2011-4347"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4594" ref_id="CVE-2011-4594"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4611" ref_id="CVE-2011-4611"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0038" ref_id="CVE-2012-0038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0045" ref_id="CVE-2012-0045"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0207" ref_id="CVE-2012-0207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4077" ref_id="CVE-2011-4077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4132" ref_id="CVE-2011-4132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4622" ref_id="CVE-2011-4622"/>
        <description>[2.6.32-220.7.1.el6]
- [netdrv] tg3: Fix single-vector MSI-X code (John Feeney) [787162 703555]
- [mm] export remove_from_page_cache() to modules (Jerome Marchand) [772687 751419]
- [block] cfq-iosched: fix cfq_cic_link() race confition (Vivek Goyal) [786022 765673]
- [fs] cifs: lower default wsize when unix extensions are not used (Jeff Layton) [789058 773705]
- [net] svcrpc: fix double-free on shutdown of nfsd after changing pool mode (J. Bruce Fields) [787580 753030]
- [net] svcrpc: avoid memory-corruption on pool shutdown (J. Bruce Fields) [787580 753030]
- [net] svcrpc: destroy server sockets all at once (J. Bruce Fields) [787580 753030]
- [net] svcrpc: simplify svc_close_all (J. Bruce Fields) [787580 753030]
- [net] svcrpc: fix list-corrupting race on nfsd shutdown (J. Bruce Fields) [787580 753030]
- [fs] xfs: Fix missing xfs_iunlock() on error recovery path in xfs_readlink() (Carlos Maiolino) [749161 694702] {CVE-2011-4077}
- [fs] xfs: Fix memory corruption in xfs_readlink (Carlos Maiolino) [749161 694702] {CVE-2011-4077}
- [x86] hpet: Disable per-cpu hpet timer if ARAT is supported (Prarit Bhargava) [772884 750201]
- [x86] Improve TSC calibration using a delayed workqueue (Prarit Bhargava) [772884 750201]
- [kernel] clocksource: Add clocksource_register_hz/khz interface (Prarit Bhargava) [772884 750201]
- [kernel] clocksource: Provide a generic mult/shift factor calculation (Prarit Bhargava) [772884 750201]
- [block] cfq-iosched: fix a kbuild regression (Vivek Goyal) [769208 705698]
- [block] cfq-iosched: rethink seeky detection for SSDs (Vivek Goyal) [769208 705698]
- [block] cfq-iosched: rework seeky detection (Vivek Goyal) [769208 705698]
- [block] cfq-iosched: don't regard requests with long distance as close (Vivek Goyal) [769208 705698]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:44:58.762-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:34.571-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:06.469-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:19:33.090-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:19:33.090-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:132460"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:132166"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:132687"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:132272"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:132475"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:132126"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:132436"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:132730"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:132271"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27855" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0467 -- freetype security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0467.html" ref_id="ELSA-2012-0467"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1126" ref_id="CVE-2012-1126"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1127" ref_id="CVE-2012-1127"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1130" ref_id="CVE-2012-1130"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1131" ref_id="CVE-2012-1131"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1132" ref_id="CVE-2012-1132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1134" ref_id="CVE-2012-1134"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1136" ref_id="CVE-2012-1136"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1137" ref_id="CVE-2012-1137"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1139" ref_id="CVE-2012-1139"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1140" ref_id="CVE-2012-1140"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1141" ref_id="CVE-2012-1141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1142" ref_id="CVE-2012-1142"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1143" ref_id="CVE-2012-1143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1144" ref_id="CVE-2012-1144"/>
        <description>[2.3.11-6.el6_2.9]
- Fix CVE-2012-{1126, 1127, 1130, 1131, 1132, 1134, 1136,
  1137, 1139, 1140, 1141, 1142, 1143, 1144}
- Properly initialize array 'result' in
  FT_Outline_Get_Orientation()
- Check bytes per row for overflow in _bdf_parse_glyphs()
- Resolves: #806268</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:29.366-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:32.978-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:05.974-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:41:52.548-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:41:52.548-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="freetype is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:132074"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:132513"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:132386"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:132212"/>
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:132399"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:132585"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27853" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1434 -- icedtea-web security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1434.html" ref_id="ELSA-2012-1434"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4540" ref_id="CVE-2012-4540"/>
        <description>[1.2.2-1]
- Updated to 1.2.2
- Resolves: CVE-2012-4540</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:28.431-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:32.229-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:05.608-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:00:40.064-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:00:40.064-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="icedtea-web is earlier than 0:1.2.2-1.el6_3" test_ref="oval:org.mitre.oval:tst:130388"/>
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.2.2-1.el6_3" test_ref="oval:org.mitre.oval:tst:130988"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27851" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1206 -- python-paste-script security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python-paste-script</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1206.html" ref_id="ELSA-2012-1206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0878" ref_id="CVE-2012-0878"/>
        <description>[1.7.3-5]
- fix group permissions in serve.py
Resolves: CVE-2012-0878</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:15.134-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:32.020-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:05.488-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:22:06.024-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:22:06.024-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="python-paste-script is earlier than 0:1.7.3-5.el6_3" test_ref="oval:org.mitre.oval:tst:131344"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27849" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0958 -- sos security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sos</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0958.html" ref_id="ELSA-2012-0958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2664" ref_id="CVE-2012-2664"/>
        <description>[2.2-29.0.1.el6]
- Direct traceroute to linux.oracle.com (John Haxby) [orabug 11713272]
- Disable --upload option as it will not work with Oracle support
- Check oraclelinux-release instead of redhat-release to get OS version (John Haxby) [bug 11681869]
- Remove RH ftp URL and support email
- add sos-oracle-enterprise.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:14.767-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:31.614-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:05.304-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:27:15.365-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:27:15.365-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="sos is earlier than 0:2.2-29.0.1.el6" test_ref="oval:org.mitre.oval:tst:131753"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27848" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1259 -- quagga security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1259.html" ref_id="ELSA-2012-1259"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3323" ref_id="CVE-2011-3323"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3324" ref_id="CVE-2011-3324"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3325" ref_id="CVE-2011-3325"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3326" ref_id="CVE-2011-3326"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3327" ref_id="CVE-2011-3327"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0249" ref_id="CVE-2012-0249"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0250" ref_id="CVE-2012-0250"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0255" ref_id="CVE-2012-0255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1820" ref_id="CVE-2012-1820"/>
        <description>[0.99.15-7.2]
- improve fix for CVE-2011-3325

[0.99.15-7.1]
- fix CVE-2011-3323
- fix CVE-2011-3324
- fix CVE-2011-3325
- fix CVE-2011-3326
- fix CVE-2011-3327
- fix CVE-2012-0255
- fix CVE-2012-0249 and CVE-2012-0250
- fix CVE-2012-1820

[0.99.15-7]
- Resolves: #684751 - CVE-2010-1674 CVE-2010-1675 quagga various flaws

[0.99.15-6]
- Resolves: #644832 - CVE-2010-2948 CVE-2010-2949 quagga various flaws</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:40.997-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:31.222-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:05.175-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:43:28.969-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:43:28.969-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="quagga is earlier than 0:0.99.15-7.el6_3.2" test_ref="oval:org.mitre.oval:tst:131254"/>
          <criterion comment="quagga-contrib is earlier than 0:0.99.15-7.el6_3.2" test_ref="oval:org.mitre.oval:tst:131335"/>
          <criterion comment="quagga-devel is earlier than 0:0.99.15-7.el6_3.2" test_ref="oval:org.mitre.oval:tst:131069"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27846" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1248 -- ca-certificates security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ca-certificates</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1248.html" ref_id="ELSA-2011-1248"/>
        <description>[2010.63-3.5]
- BR java-openjdk

[2010.63-3.4]
- fix inclusion of code-signing-only certs in .trust.crt
- Initial build (#448497)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:27.543-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:30.780-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.996-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:44:20.706-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:44:20.706-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="ca-certificates is earlier than 0:2010.63-3.el6_1.5" test_ref="oval:org.mitre.oval:tst:133496"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27843" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0884 -- openssh security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0884.html" ref_id="ELSA-2012-0884"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5000" ref_id="CVE-2011-5000"/>
        <description>[5.3p1-81]
- fixes in openssh-5.3p1-required-authentications.patch (#657378)

[5.3p1-79]
- fix forward on non-localhost ports with IPv6 (#732955)

[5.3p1-78]
- clear SELinux exec context before exec passwd (#814691)

[5.3p1-77]
- prevent post-auth resource exhaustion (#809938)

[5.3p1-76]
- don't escape backslah in a banner (#809619)

[5.3p1-75]
- fix various issues in openssh-5.3p1-required-authentications.patch (#805901)

[5.3p1-74]
- fix out-of-memory killer patch (#744236)

[5.3p1-73]
- remove openssh-4.3p2-no-v6only.patch (#732955)
- adjust Linux out-of-memory killer (#744236)
- fix sshd init script - check existence of crypto (#797384)
- add RequiredAuthentications[12] (#657378)
- run privsep slave process as the users SELinux context (#798241)

[5.3p1-72]
- drop CAVS test driver (#782091)

[5.3p1-71]
- enable aes-ctr ciphers use the EVP engines from OpenSSL such as the AES-NI (#756929)
- add CAVS test driver for the aes-ctr ciphers (#782091)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:15.540-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:30.124-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.742-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:40:40.528-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:40:40.528-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssh is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:131718"/>
          <criterion comment="openssh-askpass is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:131777"/>
          <criterion comment="openssh-clients is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:130800"/>
          <criterion comment="openssh-ldap is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:131250"/>
          <criterion comment="openssh-server is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:131524"/>
          <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9-81.el6" test_ref="oval:org.mitre.oval:tst:131682"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27842" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2001 -- Unbreakable Enterprise kernel security and bug fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
          <product>mlnx_en</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2001.html" ref_id="ELSA-2012-2001"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0056" ref_id="CVE-2012-0056"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2962" ref_id="CVE-2010-2962"/>
        <description>[2.6.32-300.7.1.el6uek] - Revert "proc: enable writing to /proc/pid/mem"
          [orabug 13619701] {CVE-2012-0056} - [PATCH] x86, tsc: Skip TSC synchronization checks for
          tsc=reliable (Suresh Siddha) [2.6.32-300.6.1.el6uek] - tracing: Fix null pointer deref
          with SEND_SIG_FORCED (Oleg Nesterov) [orabug 13611655] [2.6.32-300.5.1.el6uek] - sched,
          x86: Avoid unnecessary overflow in sched_clock (Salman Qazi) [orabug 13604567] - [x86]:
          Don't resume/restore cpu if not of the expected cpu (Joe Jin) [orabug 13492670] -
          drm/i915: Rephrase pwrite bounds checking to avoid any potential overflow (Chris Wilson)
          [CVE-2010-296] - x2apic: Enable the bios request for x2apic optout (Suresh Siddha) [orabug
          13565303] - fuse: split queues to scale I/O throughput (Srinivas Eeda) [orabug 10004611] -
          fuse: break fc spinlock (Srinivas Eeda) [orabug 10004611]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:04.211-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:29.773-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.584-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36492 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:39.316-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:37.013-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131969"/>
            <criterion comment="ofa-2.6.32-300.7.1.el5uek is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132355"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132632"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132857"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132620"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132378"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132327"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132661"/>
            <criterion comment="ofa-2.6.32-300.7.1.el5uekdebug is earlier than 0:1.5.1-4.0.53" test_ref="oval:org.mitre.oval:tst:132581"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132800"/>
            <criterion comment="mlnx_en-2.6.32-300.7.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132893"/>
            <criterion comment="ofa-2.6.32-300.7.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132807"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132752"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132862"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132652"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132888"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132415"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132793"/>
            <criterion comment="mlnx_en-2.6.32-300.7.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131925"/>
            <criterion comment="ofa-2.6.32-300.7.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132894"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27840" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1777 -- qemu-kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1777.html" ref_id="ELSA-2011-1777"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4111" ref_id="CVE-2011-4111"/>
        <description>[qemu-kvm-0.12.1.2-2.209.el6_2.1]
- kvm-ccid-Fix-buffer-overrun-in-handling-of-VSC_ATR-messa.patch [bz#751312]
- CVE: CVE-2011-4111
- Resolves: bz#751312
  (CVE-2011-4111 qemu: ccid: buffer overflow in handling of VSC_ATR message [rhel-6.2.z])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:35.931-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:29.452-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.481-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:13:18.260-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:13:18.260-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.209.el6_2.1" test_ref="oval:org.mitre.oval:tst:133099"/>
          <criterion comment="qemu-img is earlier than 0:0.12.1.2-2.209.el6_2.1" test_ref="oval:org.mitre.oval:tst:133110"/>
          <criterion comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.209.el6_2.1" test_ref="oval:org.mitre.oval:tst:133093"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27839" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0796 -- rsyslog security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>rsyslog</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0796.html" ref_id="ELSA-2012-0796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4623" ref_id="CVE-2011-4623"/>
        <description>[5.8.10-2]
- add patch to update information on debugging in the man page
  Resolves: #820311
- add patch to prevent debug output to stdout after forking
  Resolves: #820996
- add patch to support ssl certificates with domain names longer than 128 chars
  Resolves: #822118

[5.8.10-1]
- rebase to rsyslog 5.8.10
  Resolves: #803550
  Resolves: #805424
  Resolves: #813079
  Resolves: #813084
- consider lock file in 'status' action
  Resolves: #807608
- add impstats and imptcp modules
- include new license text files
- specify which versions of sysklogd are obsoleted

[5.8.7-1]
- rebase to rsyslog-5.8.7
  - change license from 'GPLv3+' to '(GPLv3+ and ASL 2.0)'
    http://blog.gerhards.net/2012/01/rsyslog-licensing-update.html
  - remove patches obsoleted by rebase
  - add patches for better sysklogd compatibility (taken from upstream)
  - update included files for the new major version
  Resolves: #672182
  Resolves: #727380
  Resolves: #756664
  Resolves: #767527
  Resolves: #769025
- add several directories for storing auxiliary data
  Resolves: #740420
- fix source package URL</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:11.175-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:29.178-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.379-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:46:08.228-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:46:08.228-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="rsyslog is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:131748"/>
          <criterion comment="rsyslog-gnutls is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:131742"/>
          <criterion comment="rsyslog-gssapi is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:131360"/>
          <criterion comment="rsyslog-mysql is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:131534"/>
          <criterion comment="rsyslog-pgsql is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:131791"/>
          <criterion comment="rsyslog-relp is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:131631"/>
          <criterion comment="rsyslog-snmp is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:131438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27838" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1180 -- gimp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1180.html" ref_id="ELSA-2012-1180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3403" ref_id="CVE-2012-3403"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3481" ref_id="CVE-2012-3481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2896" ref_id="CVE-2011-2896"/>
        <description>[2:2.6.9-4.3]
- fix overflow in GIF loader (#847303)

[2:2.6.9-4.2]
- fix overflows in GIF, CEL loaders (#727800, #839020)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:26.647-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:29.038-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.289-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:27:55.764-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:27:55.764-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gimp is earlier than 0:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:130457"/>
          <criterion comment="gimp-devel is earlier than 0:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:130852"/>
          <criterion comment="gimp-devel-tools is earlier than 0:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:131373"/>
          <criterion comment="gimp-help-browser is earlier than 0:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:131019"/>
          <criterion comment="gimp-libs is earlier than 0:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:131128"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27837" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0410 -- raptor security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>raptor</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0410.html" ref_id="ELSA-2012-0410"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0037" ref_id="CVE-2012-0037"/>
        <description>[1.4.18-5.1]
- Fixed XML entity expansion that could lead to information disclosure (CVE-2012-0037)
  Resolves: rhbz#804496</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:20.460-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:28.827-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.190-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:08:28.596-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:08:28.596-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="raptor is earlier than 0:1.4.18-5.el6_2.1" test_ref="oval:org.mitre.oval:tst:132506"/>
          <criterion comment="raptor-devel is earlier than 0:1.4.18-5.el6_2.1" test_ref="oval:org.mitre.oval:tst:132454"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27836" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0845 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind97</product>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0845.html" ref_id="ELSA-2011-0845"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1910" ref_id="CVE-2011-1910"/>
        <description>[32:9.7.3-2.1.P1]

- update to 9.7.3-P1 (CVE-2011-1910)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:26.147-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:28.590-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:04.072-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:02:20.885-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:02:20.885-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind97 is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133784"/>
            <criterion comment="bind97-chroot is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133503"/>
            <criterion comment="bind97-devel is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133758"/>
            <criterion comment="bind97-libs is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133400"/>
            <criterion comment="bind97-utils is earlier than 0:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:133510"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:132820"/>
            <criterion comment="bind-chroot is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:133816"/>
            <criterion comment="bind-devel is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:133671"/>
            <criterion comment="bind-libs is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:133732"/>
            <criterion comment="bind-sdb is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:133127"/>
            <criterion comment="bind-utils is earlier than 0:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:132937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27833" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0105 -- mysql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0105.html" ref_id="ELSA-2012-0105"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2262" ref_id="CVE-2011-2262"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0075" ref_id="CVE-2012-0075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0087" ref_id="CVE-2012-0087"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0101" ref_id="CVE-2012-0101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0102" ref_id="CVE-2012-0102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0112" ref_id="CVE-2012-0112"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0113" ref_id="CVE-2012-0113"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0114" ref_id="CVE-2012-0114"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0115" ref_id="CVE-2012-0115"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0116" ref_id="CVE-2012-0116"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0118" ref_id="CVE-2012-0118"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0119" ref_id="CVE-2012-0119"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0120" ref_id="CVE-2012-0120"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0484" ref_id="CVE-2012-0484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0485" ref_id="CVE-2012-0485"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0490" ref_id="CVE-2012-0490"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0492" ref_id="CVE-2012-0492"/>
        <description>[5.1.61-1.el6_2.1]
- Update to 5.1.61, for assorted upstream bugfixes including
  numerous CVEs announced in January 2012
Resolves: #787191</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:24.342-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:26.870-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:03.503-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:29:58.795-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:29:58.795-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132260"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132346"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132753"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132617"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132254"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132446"/>
          <criterion comment="mysql-server is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132707"/>
          <criterion comment="mysql-test is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132766"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27832" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1132 -- icedtea-web security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1132.html" ref_id="ELSA-2012-1132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3422" ref_id="CVE-2012-3422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3423" ref_id="CVE-2012-3423"/>
        <description>[1.2.1-1]
- Updated to 1.2.1
- Resolves: CVE-2012-3422
- Resolves: CVE-2012-3423</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:39.122-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:26.540-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:03.383-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:02:49.207-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:02:49.207-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="icedtea-web is earlier than 0:1.2.1-1.el6_3" test_ref="oval:org.mitre.oval:tst:131317"/>
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.2.1-1.el6_3" test_ref="oval:org.mitre.oval:tst:131382"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27829" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1482 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1482.html" ref_id="ELSA-2012-1482"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4201" ref_id="CVE-2012-4201"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4202" ref_id="CVE-2012-4202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4207" ref_id="CVE-2012-4207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4209" ref_id="CVE-2012-4209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4210" ref_id="CVE-2012-4210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4214" ref_id="CVE-2012-4214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4215" ref_id="CVE-2012-4215"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4216" ref_id="CVE-2012-4216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5829" ref_id="CVE-2012-5829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5830" ref_id="CVE-2012-5830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5833" ref_id="CVE-2012-5833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5835" ref_id="CVE-2012-5835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5839" ref_id="CVE-2012-5839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5840" ref_id="CVE-2012-5840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5841" ref_id="CVE-2012-5841"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5842" ref_id="CVE-2012-5842"/>
        <description>firefox
[10.0.11-1.0.1.el6_3]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[10.0.11-1]
- Update to 10.0.11 ESR

xulrunner
[10.0.11-1.0.1.el6_3]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.11-1]
- Update to 10.0.11 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:27.316-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:25.233-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:02.830-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:10:57.327-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:10:57.327-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.11-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130690"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130828"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130447"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.11-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130710"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130728"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130642"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27827" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1098 -- glibc security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1098.html" ref_id="ELSA-2012-1098"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3404" ref_id="CVE-2012-3404"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3405" ref_id="CVE-2012-3405"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3406" ref_id="CVE-2012-3406"/>
        <description>[2.12-1.80.el6_3.3]
- Fix incorrect/corrupt patchfile for 833716.  Did not
    affect generated code, but tests were missing (#833716).

[2.12-1.80.el6_3.2]
- Fix regression after patch for BZ804630 (#837026).

[2.12-1.80.el6_3.1]
- Fixes an unbound alloca and related problems. (#833716)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:21.348-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:24.981-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:02.660-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:37:28.013-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:37:28.013-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:130733"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:131016"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:131424"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:131518"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:131381"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:131279"/>
          <criterion comment="nscd is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:130614"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27825" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1102 -- pidgin security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1102.html" ref_id="ELSA-2012-1102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2318" ref_id="CVE-2012-2318"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3374" ref_id="CVE-2012-3374"/>
        <description>[2.7.9-5.el6.2]
- Add patch for CVE-2011-2485 (RH bug #837561).

[2.7.9-5.el6.1]
- Add patch for CVE-2012-1178 (RH bug #837560).
- Add patch for CVE-2012-2318 (RH bug #837560).
- Add patch for CVE-2012-3374 (RH bug #837560).

[2.7.9-5.el6]
- Add patch for CVE-2011-4602 (RH bug #766453).

[2.7.9-4.el6]
- Add patch for CVE-2011-4601 (RH bug #766453).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:24.782-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:24.534-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:02.470-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:15:24.598-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:15:24.598-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pidgin is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:131374"/>
          <criterion comment="finch is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:131170"/>
          <criterion comment="finch-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:130864"/>
          <criterion comment="libpurple is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:130734"/>
          <criterion comment="libpurple-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:131554"/>
          <criterion comment="libpurple-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:131510"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:131566"/>
          <criterion comment="pidgin-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:131476"/>
          <criterion comment="pidgin-docs is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:131244"/>
          <criterion comment="pidgin-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:131493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27822" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0997 -- 389-ds-base security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0997.html" ref_id="ELSA-2012-0997"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2678" ref_id="CVE-2012-2678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2746" ref_id="CVE-2012-2746"/>
        <description>[1.2.10.2-18]
- Resolves: Bug 830001 - unhashed#user#password visible after changing password
-- patch 0020 disallows users' direct modify on unhashed#user#password

[1.2.10.2-17]
- Resolves: Bug 830001 - unhashed#user#password visible after changing password
-- patch 0019 fixes deref issue.

[1.2.10.2-16]
- Resolves: Bug 830001 - unhashed#user#password visible after changing password
- Resolves: Bug 830256 - Audit log - clear text password in user changes</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:17.413-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:23.911-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:02.183-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:30:38.342-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:30:38.342-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="389-ds-base is earlier than 0:1.2.10.2-18.el6_3" test_ref="oval:org.mitre.oval:tst:131531"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.10.2-18.el6_3" test_ref="oval:org.mitre.oval:tst:131644"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.10.2-18.el6_3" test_ref="oval:org.mitre.oval:tst:131714"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27821" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0716 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0716.html" ref_id="ELSA-2012-0716"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1033" ref_id="CVE-2012-1033"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1667" ref_id="CVE-2012-1667"/>
        <description>[32:9.7.3-8.P3.3]
- fix CVE-2012-1667 and CVE-2012-1033</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:04.402-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:23.535-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:02.031-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:56:48.840-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:56:48.840-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131621"/>
            <criterion comment="bind-chroot is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131928"/>
            <criterion comment="bind-devel is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131390"/>
            <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131967"/>
            <criterion comment="bind-libs is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131253"/>
            <criterion comment="bind-sdb is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131826"/>
            <criterion comment="bind-utils is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131813"/>
            <criterion comment="caching-nameserver is earlier than 0:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:131670"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131757"/>
            <criterion comment="bind-chroot is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131367"/>
            <criterion comment="bind-devel is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131627"/>
            <criterion comment="bind-libs is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:132014"/>
            <criterion comment="bind-sdb is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131976"/>
            <criterion comment="bind-utils is earlier than 0:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:131617"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27820" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1283 -- openjpeg security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openjpeg</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1283.html" ref_id="ELSA-2012-1283"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3535" ref_id="CVE-2012-3535"/>
        <description>[1.3-9]
- Apply patch for CVE-2012-3535
Resolves: CVE-2012-3535</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:37.009-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:23.313-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:01.935-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:55:23.843-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:55:23.843-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openjpeg is earlier than 0:1.3-9.el6_3" test_ref="oval:org.mitre.oval:tst:130572"/>
          <criterion comment="openjpeg-devel is earlier than 0:1.3-9.el6_3" test_ref="oval:org.mitre.oval:tst:130533"/>
          <criterion comment="openjpeg-libs is earlier than 0:1.3-9.el6_3" test_ref="oval:org.mitre.oval:tst:131132"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27819" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1338 -- NetworkManager security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>NetworkManager</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1338.html" ref_id="ELSA-2011-1338"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3364" ref_id="CVE-2011-3364"/>
        <description>[0.8.1-9_el6_1.3]
- ifcfg-rh: CVE-2011-3364: filter newline characters when writing into ifcfg-* files (rh #737338)

[0.8.1-9_el6_1.2]
- ifcfg-rh: CVE-2011-3364: filter newline characters when writing into ifcfg-* files (rh #737338)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:35.588-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:23.071-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:01.814-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:44:50.260-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:44:50.260-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="NetworkManager is earlier than 0:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:133318"/>
          <criterion comment="NetworkManager-devel is earlier than 0:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:132909"/>
          <criterion comment="NetworkManager-glib is earlier than 0:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:132535"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 0:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:133142"/>
          <criterion comment="NetworkManager-gnome is earlier than 0:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:132924"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27816" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1533 -- ipa security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ipa</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1533.html" ref_id="ELSA-2011-1533"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3636" ref_id="CVE-2011-3636"/>
        <description>[2.1.3-9.el6]
- Add current password prompt when changing own password in web UI (#751179)
- Remove extraneous trailing ' from netgroup patch (#749352)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:23.622-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:22.319-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:01.374-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:09:58.125-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:09:58.125-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ipa is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:132996"/>
          <criterion comment="ipa-admintools is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:133039"/>
          <criterion comment="ipa-client is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:132778"/>
          <criterion comment="ipa-python is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:133089"/>
          <criterion comment="ipa-server is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:132901"/>
          <criterion comment="ipa-server-selinux is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:133052"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27815" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0143 -- xulrunner security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0143.html" ref_id="ELSA-2012-0143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3026" ref_id="CVE-2011-3026"/>
        <description>[1.9.2.26-2.0.1.el6_2]
- Replace xulrunner-redhat-default-prefs.js with
  xulrunner-oracle-default-prefs.js

[1.9.2.26-2]
- added fix for mozbz#727401</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:16.279-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:22.184-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:01.302-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:29:59.908-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:29:59.908-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:132244"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.0.1.el5_7" test_ref="oval:org.mitre.oval:tst:132699"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132013"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27811" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0518 -- openssl security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0518.html" ref_id="ELSA-2012-0518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2110" ref_id="CVE-2012-2110"/>
        <description>openssl:
[1.0.0-20.4]
- fix for CVE-2012-2110 - memory corruption in asn1_d2i_read_bio() (#814185)

openssl098e:
[0.9.8e-17.el6_2.2]
- Updated the description

[0.9.8e-17.2]
- fix for CVE-2012-2110 - memory corruption in asn1_d2i_read_bio() (#814185)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:24.303-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:21.354-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:00.848-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:21:53.506-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:21:53.506-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:132381"/>
            <criterion comment="openssl097a is earlier than 0:0.9.7a-11.el5_8.2" test_ref="oval:org.mitre.oval:tst:132116"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:132237"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:132168"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:132515"/>
            <criterion comment="openssl098e is earlier than 0:0.9.8e-17.0.1.el6_2.2" test_ref="oval:org.mitre.oval:tst:132478"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:131522"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:132287"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:132497"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27809" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0515 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0515.html" ref_id="ELSA-2012-0515"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0467" ref_id="CVE-2012-0467"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0468" ref_id="CVE-2012-0468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0469" ref_id="CVE-2012-0469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0470" ref_id="CVE-2012-0470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0471" ref_id="CVE-2012-0471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0472" ref_id="CVE-2012-0472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0473" ref_id="CVE-2012-0473"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0474" ref_id="CVE-2012-0474"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0477" ref_id="CVE-2012-0477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0478" ref_id="CVE-2012-0478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0479" ref_id="CVE-2012-0479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3062" ref_id="CVE-2011-3062"/>
        <description>firefox:
[10.0.4-1.0.1.el6_2]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.4-1]
- Update to 10.0.4 ESR

xulrunner:
[10.0.4-1.0.1.el6_2]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.4-1]
- Update to 10.0.4 ESR

[10.0.3-3]
- Fixed mozbz#746112 - ppc(64) freeze

[10.0.3-2]
- Fixed mozbz#681937</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:13.344-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:19.939-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:00.317-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:31:32.414-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:31:32.414-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.4-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132261"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132283"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132409"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.4-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131881"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132296"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132301"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27808" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0842 -- systemtap security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0842.html" ref_id="ELSA-2011-0842"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1769" ref_id="CVE-2011-1769"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1781" ref_id="CVE-2011-1781"/>
        <description>[1.4.6.0.1.el6_1.1]
- remove doc/SystemTap_Beginners_Guide/en-US in tarball
- comment bz683569.patch in specfile

[1.3-4.1]
- bz702687 (patch)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:40.686-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:19.692-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:03:00.134-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:12:42.539-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:12:42.539-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="systemtap is earlier than 0:1.4-6.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133569"/>
          <criterion comment="systemtap-client is earlier than 0:1.4-6.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133753"/>
          <criterion comment="systemtap-grapher is earlier than 0:1.4-6.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133641"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.4-6.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133356"/>
          <criterion comment="systemtap-runtime is earlier than 0:1.4-6.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133211"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.4-6.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133744"/>
          <criterion comment="systemtap-server is earlier than 0:1.4-6.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133726"/>
          <criterion comment="systemtap-testsuite is earlier than 0:1.4-6.0.1.el6_1.1" test_ref="oval:org.mitre.oval:tst:133599"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27807" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0678 -- postgresql and postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0678.html" ref_id="ELSA-2012-0678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0867" ref_id="CVE-2012-0867"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0866" ref_id="CVE-2012-0866"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0868" ref_id="CVE-2012-0868"/>
        <description>[8.4.11-1]
- Update to PostgreSQL 8.4.11, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-11.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-10.html
  including the fixes for CVE-2012-0866, CVE-2012-0867, CVE-2012-0868
Resolves: #812081</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:27.487-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:19.189-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:59.886-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:41:00.295-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:41:00.295-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132157"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132231"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131877"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132239"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132179"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131805"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131303"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131602"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132155"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131384"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:131950"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:132136"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132041"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132052"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132174"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132120"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132193"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132109"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:131601"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:131739"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132128"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:132217"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27804" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1384 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1384.html" ref_id="ELSA-2012-1384"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3216" ref_id="CVE-2012-3216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4416" ref_id="CVE-2012-4416"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5068" ref_id="CVE-2012-5068"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5069" ref_id="CVE-2012-5069"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5071" ref_id="CVE-2012-5071"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5072" ref_id="CVE-2012-5072"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5073" ref_id="CVE-2012-5073"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5075" ref_id="CVE-2012-5075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5077" ref_id="CVE-2012-5077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5079" ref_id="CVE-2012-5079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5081" ref_id="CVE-2012-5081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5084" ref_id="CVE-2012-5084"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5085" ref_id="CVE-2012-5085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5086" ref_id="CVE-2012-5086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5089" ref_id="CVE-2012-5089"/>
        <description>[1:1.6.0.0-1.50.1.11.5]
- Changed permissions of sa-jdi.jar to correct 644
- Resolves: rhbz#865045

[1:1.6.0.0-1.49.1.11.5]
- Updated to IcedTea6 1.11.5
- Resolves rhbz#s 856124, 865346, 865348, 865350, 865352, 865354, 865357,
  865359, 865363, 865365, 865370, 865428, 865471, 865434, 865511, 865514,
  865519, 865531, 865541, 865568</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:42.428-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:17.240-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:59.082-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:32:56.130-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:32:56.130-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:131075"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:130721"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:131006"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:131096"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:130951"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27803" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0872 -- glibc security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0872.html" ref_id="ELSA-2010-0872"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3847" ref_id="CVE-2010-3847"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3856" ref_id="CVE-2010-3856"/>
        <description>[2.12-1.7.el6_0.3]
- Require suid bit on audit objects in privileged programs (#645679,
  CVE-2010-3856)

[2.12-1.7.el6_0.2]
- Never expand  in privileged programs (#643821)

[2.12-1.7.el6_0.1]
- Fix bug in generic strstr/memmem implementation handling certain
  repeated patterns (#643341)
- Correctly align TCB for AVX (#643343)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:40.294-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:16.991-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:58.955-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:43:53.913-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:43:53.913-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:133736"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:134223"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:134362"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:134167"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:134147"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:133468"/>
          <criterion comment="nscd is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:134113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27802" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0890 -- pidgin security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0890.html" ref_id="ELSA-2010-0890"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3711" ref_id="CVE-2010-3711"/>
        <description>[2.6.6-6.el6]
- Add patch for CVE-2010-3711 (RH bug #645413).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:02.148-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:16.711-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:58.844-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:21:45.359-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:21:45.359-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pidgin is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134411"/>
          <criterion comment="finch is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134144"/>
          <criterion comment="finch-devel is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134107"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134424"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134409"/>
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134446"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134372"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134089"/>
          <criterion comment="pidgin-docs is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134311"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:134369"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27801" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1530 -- Oracle Linux 6 kernel security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1530.html" ref_id="ELSA-2011-1530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1020" ref_id="CVE-2011-1020"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3347" ref_id="CVE-2011-3347"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3638" ref_id="CVE-2011-3638"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4110" ref_id="CVE-2011-4110"/>
        <description>[2.6.32-220.el6]
- [drm] i915: fix unmap race condition introduced with VT-d fix (Dave Airlie) [750583]
- [scsi] iscsi: revert lockless queuecommand dispatch (Rob Evers) [751426]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:34.566-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:16.352-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:58.681-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:132982"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:133014"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:132928"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:132932"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:132840"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:132919"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:132635"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:133109"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:132814"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27800" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0429 -- gnutls security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0429.html" ref_id="ELSA-2012-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4128" ref_id="CVE-2011-4128"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1573" ref_id="CVE-2012-1573"/>
        <description>[2.8.5-4.2]
- fix CVE-2012-1573 - security issue in packet parsing (#805432)
- fix CVE-2011-4128 - buffer overflow in gnutls_session_get_data() (#752308)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:14.296-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:16.071-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:58.419-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:26:19.574-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:26:19.574-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gnutls is earlier than 0:2.8.5-4.el6_2.2" test_ref="oval:org.mitre.oval:tst:132542"/>
          <criterion comment="gnutls-devel is earlier than 0:2.8.5-4.el6_2.2" test_ref="oval:org.mitre.oval:tst:132379"/>
          <criterion comment="gnutls-guile is earlier than 0:2.8.5-4.el6_2.2" test_ref="oval:org.mitre.oval:tst:132105"/>
          <criterion comment="gnutls-utils is earlier than 0:2.8.5-4.el6_2.2" test_ref="oval:org.mitre.oval:tst:132395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27796" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0455 -- polkit security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>polkit</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0455.html" ref_id="ELSA-2011-0455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1485" ref_id="CVE-2011-1485"/>
        <description>[0.96-2.el6_0.1]
- Include fixes for CVE-2011-1485
- Resolves: #692941</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:55.474-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:15.591-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:58.122-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:53:48.292-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:53:48.292-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="polkit is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:133984"/>
          <criterion comment="polkit-desktop-policy is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:133791"/>
          <criterion comment="polkit-devel is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134068"/>
          <criterion comment="polkit-docs is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134042"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27787" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1263 -- postgresql and postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1263.html" ref_id="ELSA-2012-1263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3488" ref_id="CVE-2012-3488"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3489" ref_id="CVE-2012-3489"/>
        <description>[8.4.13-1]
- Update to PostgreSQL 8.4.13, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-13.html
  including the fixes for CVE-2012-3488, CVE-2012-3489
Resolves: #852020</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:34.330-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:14.122-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:57.216-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:21:00.109-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:21:00.109-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:130478"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131259"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131028"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131032"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:130428"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131193"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131002"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:130747"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131149"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:130351"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131064"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:131131"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131310"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131217"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131218"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131039"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:130959"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131349"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:130708"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:130961"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131045"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:131350"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27783" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0137 -- texlive security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>texlive</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0137.html" ref_id="ELSA-2012-0137"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2642" ref_id="CVE-2010-2642"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0433" ref_id="CVE-2011-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0764" ref_id="CVE-2011-0764"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1552" ref_id="CVE-2011-1552"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1553" ref_id="CVE-2011-1553"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1554" ref_id="CVE-2011-1554"/>
        <description>[2007-57]
- fix CVE-2010-2642 CVE-2011-0433 CVE-2011-0764 CVE-2011-1552
  CVE-2011-1553 CVE-2011-1554, texlive various flaws (#773183)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:15.343-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:13.263-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:56.837-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:17:37.922-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:17:37.922-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="texlive is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132559"/>
          <criterion comment="kpathsea is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132645"/>
          <criterion comment="kpathsea-devel is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132658"/>
          <criterion comment="mendexk is earlier than 0:2.6e-57.el6_2" test_ref="oval:org.mitre.oval:tst:132316"/>
          <criterion comment="texlive-afm is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132133"/>
          <criterion comment="texlive-context is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132654"/>
          <criterion comment="texlive-dvips is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132602"/>
          <criterion comment="texlive-dviutils is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132467"/>
          <criterion comment="texlive-east-asian is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132396"/>
          <criterion comment="texlive-latex is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132649"/>
          <criterion comment="texlive-utils is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132591"/>
          <criterion comment="texlive-xetex is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:132605"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27782" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1694 -- libcap security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libcap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1694.html" ref_id="ELSA-2011-1694"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4099" ref_id="CVE-2011-4099"/>
        <description>[2.16-5.5]
- remove some obsolete parameters from capsh manpage

[2.16-5.4]
- add capsh manpage (#730957)

[2.16-5.3]
- make sure to chdir ('/') after calling chroot
  http://cwe.mitre.org/data/definitions/243.html</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:18.353-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:13.043-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:56.753-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libcap is earlier than 0:2.16-5.5.el6" test_ref="oval:org.mitre.oval:tst:132597"/>
          <criterion comment="libcap-devel is earlier than 0:2.16-5.5.el6" test_ref="oval:org.mitre.oval:tst:132648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27779" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0874 -- mysql security and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0874.html" ref_id="ELSA-2012-0874"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2102" ref_id="CVE-2012-2102"/>
        <description>[5.1.61-4]
- Add backported patch for CVE-2012-2102
Resolves: #812435

[5.1.61-3]
- Enable innodb plugin, but only on x86 and x86_64 architectures
Resolves: #740224</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:34.022-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:11.936-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:56.272-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:35:39.676-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:35:39.676-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:131464"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:131685"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:131759"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:131436"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:131655"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:131101"/>
          <criterion comment="mysql-server is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:131799"/>
          <criterion comment="mysql-test is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:131724"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27778" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2039 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2039.html" ref_id="ELSA-2012-2039"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <description>[2.6.39-200.33.1]

- sfc: Replace some literal constants with EFX_PAGE_SIZE/EFX_BUF_SIZE (Ben Hutchings) [Orabug: 14769994]

- CVE-2012-3412 sfc: Fix maximum number of TSO segments and minimum TX queue size (Ben Hutchings) [Orabug: 14769994] {CVE-2012-3412}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:52.476-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:11.743-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:56.119-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130673"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130762"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:131014"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130863"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130861"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.33.1.el5uek" test_ref="oval:org.mitre.oval:tst:130956"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130922"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130882"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130526"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130550"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130797"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.33.1.el6uek" test_ref="oval:org.mitre.oval:tst:130983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27776" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0544 -- ImageMagick security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0544.html" ref_id="ELSA-2012-0544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4167" ref_id="CVE-2010-4167"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0247" ref_id="CVE-2012-0247"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0248" ref_id="CVE-2012-0248"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0259" ref_id="CVE-2012-0259"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0260" ref_id="CVE-2012-0260"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1798" ref_id="CVE-2012-1798"/>
        <description>[6.5.4.7-6]
- Add fix for CVE-2010-4167
- Add fix for CVE-2012-0247 CVE-2012-0248 CVE-2012-1185 CVE-2012-1186
- Add fix for CVE-2012-0259 CVE-2012-0260 CVE-2012-1798</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:26.725-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:10.978-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:55.827-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:06:38.085-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:06:38.085-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ImageMagick is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:132249"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:131974"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:131774"/>
          <criterion comment="ImageMagick-devel is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:132142"/>
          <criterion comment="ImageMagick-doc is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:132100"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:132266"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27774" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1221 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1221.html" ref_id="ELSA-2012-1221"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0547" ref_id="CVE-2012-0547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1682" ref_id="CVE-2012-1682"/>
        <description>[1:1.6.0.0-1.49.1.11.4]
- Updated to latest IedTea6 1.11.4
- Resolves: rhbz#853345

[1:1.6.0.0-1.48.1.11.3]
- Access gnome bridge jar is forced to have 644 permissions
- Resolves: rhbz#828752

[1:1.6.0.0-1.47.1.11.3]
- Modified patch3, java-1.6.0-openjdk-java-access-bridge-security.patch:
  - com.sun.org.apache.xerces.internal.utils.,com.sun.org.apache.xalan.internal.utils.
  - packages added also to package.definition
- Resolves: rhbz#828752

[1:1.6.0.0-1.46.1.11.3]
- Updated to IcedTea6 1.11.3
- Removed upstreamed patch8 - java-1.6.0-openjdk-jirafix_2820_2821.patch
- Modified patch3, java-1.6.0-openjdk-java-access-bridge-security.patch:
  - com.sun.org.apache.xerces.internal.utils.,com.sun.org.apache.xalan.internal.utils.
  - packages added to patch
- Resolves: rhbz#828752</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:31.700-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:10.840-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:55.741-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:18:21.006-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:18:21.006-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:131067"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:131223"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:130902"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:131222"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:131099"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27773" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0810 -- busybox security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>busybox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0810.html" ref_id="ELSA-2012-0810"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2716" ref_id="CVE-2011-2716"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1168" ref_id="CVE-2006-1168"/>
        <description>[1:1.15.1-15]
- Fix btrfs support to findfs and related applets
- Resolves: #751927

[1:1.15.1-14]
- Resolves: #790335 'busybox various flaws'
  Added a fix for SEGV on empty command in hush

[1:1.15.1-13]
- Resolves: #790335 'busybox various flaws' including:
  'buffer underflow in decompression'
  'udhcpc insufficient checking of DHCP options'

[1:1.15.1-12]
- Backport 'set -o pipefail' support
- Resolves: #782018
- Add btrfs support to findfs and related applets
- Resolves: #751927</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:32.963-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:10.696-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:55.657-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:00:27.217-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:00:27.217-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="busybox is earlier than 0:1.15.1-15.el6" test_ref="oval:org.mitre.oval:tst:131330"/>
          <criterion comment="busybox-petitboot is earlier than 0:1.15.1-15.el6" test_ref="oval:org.mitre.oval:tst:131025"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27771" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1413 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1413.html" ref_id="ELSA-2012-1413"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4194" ref_id="CVE-2012-4194"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4195" ref_id="CVE-2012-4195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4196" ref_id="CVE-2012-4196"/>
        <description>[10.0.10-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[10.0.10-1]
- Update to 10.0.10 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:32.784-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:10.287-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:55.501-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:06:34.119-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:06:34.119-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130929"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130848"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27769" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0069 -- ruby security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0069.html" ref_id="ELSA-2012-0069"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4815" ref_id="CVE-2011-4815"/>
        <description>[1.8.7.352-4]
- Address CVE-2011-4815 'DoS (excessive CPU use) via hash meet-in-the-middle
  attacks (oCERT-2011-003)'
  * ruby-1.8.7-p352-CVE-2011-4815.patch
- Resolves: rhbz#768831</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:02.808-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:10.032-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:55.389-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:12:00.124-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:12:00.124-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:132858"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:132822"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:132825"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:132806"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:132580"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:132210"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:132788"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:132826"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:132759"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27766" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0729 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0729.html" ref_id="ELSA-2012-0729"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1711" ref_id="CVE-2012-1711"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1713" ref_id="CVE-2012-1713"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1716" ref_id="CVE-2012-1716"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1717" ref_id="CVE-2012-1717"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1718" ref_id="CVE-2012-1718"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1719" ref_id="CVE-2012-1719"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1723" ref_id="CVE-2012-1723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1724" ref_id="CVE-2012-1724"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1725" ref_id="CVE-2012-1725"/>
        <description>[1:1.6.0.0-1.48.1.11.3]
- Access gnome bridge jar is forced to have 644 permissions
- Resolves: rhbz#828751

[1:1.6.0.0-1.47.1.11.3]
- Modified patch3, java-1.6.0-openjdk-java-access-bridge-security.patch:
  - com.sun.org.apache.xerces.internal.utils.,com.sun.org.apache.xalan.internal.utils.
  - packages added also to package.definition
- Resolves: rhbz#828751

[1:1.6.0.0-1.46.1.11.3]
- Sync with 6.3:
- Bump to IcedTea6 1.11.3
- With removed patch8 - java-1.6.0-openjdk-jirafix_2820_2821.patch
- Including patch7 - java-1.6.0-openjdk-jstack.patch
- Including patch3, java-1.6.0-openjdk-java-access-bridge-security.patch modification
- Resolves: rhbz#828751</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:13.284-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:08.610-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:54.890-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:06:48.858-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:06:48.858-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:131979"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:131987"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:131764"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:131738"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:132004"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27764" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0779 -- avahi security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>avahi</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0779.html" ref_id="ELSA-2011-0779"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1002" ref_id="CVE-2011-1002"/>
        <description>[0.6.25-11]
- Fix for CVE-2011-1002
- Resolves: #684886
- Actually apply the patch

[0.6.25-10]
- Fix for CVE-2011-1002
- Resolves: #684886

[0.6.25-9]
- Don't stomp on rpm's default CFLAGS when building</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:39">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:41.507-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:08.277-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:54.751-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:01:51.491-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:01:51.491-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="avahi is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133850"/>
          <criterion comment="avahi-autoipd is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133883"/>
          <criterion comment="avahi-compat-howl is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133465"/>
          <criterion comment="avahi-compat-howl-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133835"/>
          <criterion comment="avahi-compat-libdns_sd is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133757"/>
          <criterion comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133622"/>
          <criterion comment="avahi-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133943"/>
          <criterion comment="avahi-dnsconfd is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133696"/>
          <criterion comment="avahi-glib is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133670"/>
          <criterion comment="avahi-glib-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133560"/>
          <criterion comment="avahi-gobject is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133572"/>
          <criterion comment="avahi-gobject-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133222"/>
          <criterion comment="avahi-libs is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133825"/>
          <criterion comment="avahi-qt3 is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133619"/>
          <criterion comment="avahi-qt3-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133866"/>
          <criterion comment="avahi-qt4 is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133627"/>
          <criterion comment="avahi-qt4-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133916"/>
          <criterion comment="avahi-tools is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133767"/>
          <criterion comment="avahi-ui is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133449"/>
          <criterion comment="avahi-ui-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133563"/>
          <criterion comment="avahi-ui-tools is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:133472"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27763" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0894 -- systemtap security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0894.html" ref_id="ELSA-2010-0894"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4170" ref_id="CVE-2010-4170"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4171" ref_id="CVE-2010-4171"/>
        <description>[1.2-11.0.1.el6_0]

- rebuild without docs

- remove doc/SystemTap_Beginners_Guide/en-US in tarball



[1.2-11]

- CVE-2010-4170

- CVE-2010-4171</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:43.150-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:07.849-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:54.557-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:02:11.263-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:02:11.263-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134754"/>
            <criterion comment="systemtap-client is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:133964"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134809"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134262"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134587"/>
            <criterion comment="systemtap-server is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134376"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:134768"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134780"/>
            <criterion comment="systemtap-client is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134629"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134861"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134738"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134805"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134850"/>
            <criterion comment="systemtap-server is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134866"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.2-11.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:134822"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27761" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1288 -- libxml2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1288.html" ref_id="ELSA-2012-1288"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3102" ref_id="CVE-2011-3102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2807" ref_id="CVE-2012-2807"/>
        <description>[2.7.6-8.0.1.el6_3.3 ]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[2.7.6-8.el6_3.3]
- Change the XPath code to percolate allocation error (CVE-2011-1944)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:33.673-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:07.188-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:54.284-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:13:43.045-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:13:43.045-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131188"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130725"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.0.1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130438"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130968"/>
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:131078"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:131166"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130770"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27760" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0019 -- php53 and php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0019.html" ref_id="ELSA-2012-0019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4566" ref_id="CVE-2011-4566"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4885" ref_id="CVE-2011-4885"/>
        <description>[5.3.3-3.5]
- remove extra php.ini-prod/devel files caused by %patch -b

[5.3.3-3.4]
- add security fixes for CVE-2011-4885, CVE-2011-4566 (#769754)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:10.184-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:06.881-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:54.088-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:14:48.333-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:14:48.333-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132592"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132913"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132678"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132354"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132890"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132243"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132739"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132256"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132733"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132609"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132791"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132721"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132553"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132875"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132019"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132685"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132576"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132045"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132713"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132310"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132866"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:133004"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132593"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132886"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132655"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132988"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132048"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132905"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132444"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:133026"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:133003"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132072"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132724"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132776"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132821"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132743"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132802"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132965"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132697"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132760"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132878"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132993"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132997"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132949"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132290"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:133011"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:132774"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27759" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0465 -- kdenetwork security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kdenetwork</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0465.html" ref_id="ELSA-2011-0465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1586" ref_id="CVE-2011-1586"/>
        <description>[7:4.3.4-11.1]
- CVE-2010-1000, improper sanitization of metalink attribute for downloading files</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:04.738-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:06.663-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:53.927-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:45:55.063-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:45:55.063-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kdenetwork is earlier than 0:4.3.4-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:133913"/>
          <criterion comment="kdenetwork-devel is earlier than 0:4.3.4-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:133904"/>
          <criterion comment="kdenetwork-libs is earlier than 0:4.3.4-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:133408"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27758" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1269 -- qpid security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python-qpid</product>
          <product>qpid-cpp</product>
          <product>qpid-qmf</product>
          <product>qpid-tools</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1269.html" ref_id="ELSA-2012-1269"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2145" ref_id="CVE-2012-2145"/>
        <description>python-qpid
[0.14-11]
- BZs: 825078
- Resolves: rhbz#840053

qpid-cpp
[0.14-22.0.1.el6_3 ]
- Update summary and description in specfile to be product neutral

[0.14-22]
- BZs: 609685, 849654, 854004

[0.14-21]
- BZs: 831365, 840982, 844618

[0.14-20]
- BZs: 683711, 689408, 825078, 834608, 841196, 841488

[0.14-19]
- BZs: 609685, 683711, 693444, 707682, 729311, 801465, 808090,
       809357, 811481, 817283, 826989, 831365, 835628

[0.14-18]
- BZs: 609685, 729311, 808090, 809357, 817283

qpid-qmf
[0.14-14.0.1.el6_3]
- Change build vendor

[0.14-14]
- BZs: 693845, 773700, 806869, 847331

qpid-tools
[0.14-6]
- Resolves: rhbz#840058
- Fixed: Bug 850111 - qpid-stat -c mech column data missing</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:41.755-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:06.342-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:53.783-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:41:40.098-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:41:40.098-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="python-qpid is earlier than 0:0.14-11.el6_3" test_ref="oval:org.mitre.oval:tst:130313"/>
          <criterion comment="qpid-cpp is earlier than 0:0.14-22.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130400"/>
          <criterion comment="qpid-qmf is earlier than 0:0.14-14.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130231"/>
          <criterion comment="qpid-tools is earlier than 0:0.14-6.el6_3" test_ref="oval:org.mitre.oval:tst:131202"/>
          <criterion comment="python-qpid-qmf is earlier than 0:0.14-14.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131125"/>
          <criterion comment="qpid-cpp-client is earlier than 0:0.14-22.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131085"/>
          <criterion comment="qpid-cpp-client-ssl is earlier than 0:0.14-22.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130487"/>
          <criterion comment="qpid-cpp-server is earlier than 0:0.14-22.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131154"/>
          <criterion comment="qpid-cpp-server-ssl is earlier than 0:0.14-22.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130341"/>
          <criterion comment="ruby-qpid-qmf is earlier than 0:0.14-14.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131010"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27757" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0177 -- webkitgtk security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>webkitgtk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0177.html" ref_id="ELSA-2011-0177"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3255" ref_id="CVE-2010-3255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3257" ref_id="CVE-2010-3257"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3259" ref_id="CVE-2010-3259"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3812" ref_id="CVE-2010-3812"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3813" ref_id="CVE-2010-3813"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1780" ref_id="CVE-2010-1780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1782" ref_id="CVE-2010-1782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1783" ref_id="CVE-2010-1783"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1784" ref_id="CVE-2010-1784"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1785" ref_id="CVE-2010-1785"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1786" ref_id="CVE-2010-1786"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1787" ref_id="CVE-2010-1787"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1788" ref_id="CVE-2010-1788"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1790" ref_id="CVE-2010-1790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1792" ref_id="CVE-2010-1792"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1793" ref_id="CVE-2010-1793"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1807" ref_id="CVE-2010-1807"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1812" ref_id="CVE-2010-1812"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1814" ref_id="CVE-2010-1814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1815" ref_id="CVE-2010-1815"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3113" ref_id="CVE-2010-3113"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3114" ref_id="CVE-2010-3114"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3115" ref_id="CVE-2010-3115"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3116" ref_id="CVE-2010-3116"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3119" ref_id="CVE-2010-3119"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4197" ref_id="CVE-2010-4197"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4198" ref_id="CVE-2010-4198"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4204" ref_id="CVE-2010-4204"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4206" ref_id="CVE-2010-4206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4577" ref_id="CVE-2010-4577"/>
        <description>[1.2.6-2]
- Added fix for js regression

[1.2.6-1]
- Update to 1.2.6</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:04:00.750-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:03.458-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:52.790-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:44:10.037-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:44:10.037-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="webkitgtk is earlier than 0:1.2.6-2.el6_0" test_ref="oval:org.mitre.oval:tst:134128"/>
          <criterion comment="webkitgtk-devel is earlier than 0:1.2.6-2.el6_0" test_ref="oval:org.mitre.oval:tst:134386"/>
          <criterion comment="webkitgtk-doc is earlier than 0:1.2.6-2.el6_0" test_ref="oval:org.mitre.oval:tst:134357"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27755" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0811 -- php-pecl-apc security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php-pecl-apc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0811.html" ref_id="ELSA-2012-0811"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3294" ref_id="CVE-2010-3294"/>
        <description>[3.1.9-2]
- remove -devel package ISA multilib dependencies

[3.1.9-1]
- update to 3.1.9 (bugfix, stable) (#662655)
- create -devel subpackage with header files
- ship apc.php for easier referral in the config files</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:11.409-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:03.340-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:52.695-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:49:15.603-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:49:15.603-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php-pecl-apc is earlier than 0:3.1.9-2.el6" test_ref="oval:org.mitre.oval:tst:131746"/>
          <criterion comment="php-pecl-apc-devel is earlier than 0:3.1.9-2.el6" test_ref="oval:org.mitre.oval:tst:131445"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27753" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1424 -- perl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1424.html" ref_id="ELSA-2011-1424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2939" ref_id="CVE-2011-2939"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3597" ref_id="CVE-2011-3597"/>
        <description>[4:5.10.1-119.1]
- 731246 (CVE-2011-2939)CVE-2011-2939 heap overflow - decoding Unicode string
- 743010 - perl: code injection vulnerability in Digest->new()
- Resolves: rhbz#743090, rhbz#743092</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:16.466-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:03.028-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:52.369-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:37:00.864-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:37:00.864-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="perl is earlier than 0:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133310"/>
          <criterion comment="perl-Archive-Extract is earlier than 0:0.38-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132969"/>
          <criterion comment="perl-Archive-Tar is earlier than 0:1.58-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133192"/>
          <criterion comment="perl-CGI is earlier than 0:3.51-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133001"/>
          <criterion comment="perl-CPAN is earlier than 0:1.9402-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133154"/>
          <criterion comment="perl-CPANPLUS is earlier than 0:0.88-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132345"/>
          <criterion comment="perl-Compress-Raw-Zlib is earlier than 0:2.023-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133323"/>
          <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133288"/>
          <criterion comment="perl-Digest-SHA is earlier than 0:5.47-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133008"/>
          <criterion comment="perl-ExtUtils-CBuilder is earlier than 0:0.27-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132977"/>
          <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132903"/>
          <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132990"/>
          <criterion comment="perl-ExtUtils-ParseXS is earlier than 0:2.2003.0-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133262"/>
          <criterion comment="perl-File-Fetch is earlier than 0:0.26-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132900"/>
          <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133193"/>
          <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132884"/>
          <criterion comment="perl-IO-Zlib is earlier than 0:1.09-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132771"/>
          <criterion comment="perl-IPC-Cmd is earlier than 0:0.56-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133286"/>
          <criterion comment="perl-Locale-Maketext-Simple is earlier than 0:0.18-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132992"/>
          <criterion comment="perl-Log-Message is earlier than 0:0.02-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132376"/>
          <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133163"/>
          <criterion comment="perl-Module-Build is earlier than 0:0.3500-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133322"/>
          <criterion comment="perl-Module-CoreList is earlier than 0:2.18-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133115"/>
          <criterion comment="perl-Module-Load is earlier than 0:0.16-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133270"/>
          <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133295"/>
          <criterion comment="perl-Module-Loaded is earlier than 0:0.02-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133296"/>
          <criterion comment="perl-Module-Pluggable is earlier than 0:3.90-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133346"/>
          <criterion comment="perl-Object-Accessor is earlier than 0:0.34-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133153"/>
          <criterion comment="perl-Package-Constants is earlier than 0:0.02-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133157"/>
          <criterion comment="perl-Params-Check is earlier than 0:0.26-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133200"/>
          <criterion comment="perl-Parse-CPAN-Meta is earlier than 0:1.40-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133202"/>
          <criterion comment="perl-Pod-Escapes is earlier than 0:1.04-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133117"/>
          <criterion comment="perl-Pod-Simple is earlier than 0:3.13-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133149"/>
          <criterion comment="perl-Term-UI is earlier than 0:0.20-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133077"/>
          <criterion comment="perl-Test-Harness is earlier than 0:3.17-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133266"/>
          <criterion comment="perl-Test-Simple is earlier than 0:0.92-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133274"/>
          <criterion comment="perl-Time-HiRes is earlier than 0:1.9721-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133217"/>
          <criterion comment="perl-Time-Piece is earlier than 0:1.15-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133363"/>
          <criterion comment="perl-core is earlier than 0:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:132815"/>
          <criterion comment="perl-devel is earlier than 0:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133177"/>
          <criterion comment="perl-libs is earlier than 0:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133354"/>
          <criterion comment="perl-parent is earlier than 0:0.221-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133166"/>
          <criterion comment="perl-suidperl is earlier than 0:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133167"/>
          <criterion comment="perl-version is earlier than 0:0.77-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:133347"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27751" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0332 -- scsi-target-utils security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0332.html" ref_id="ELSA-2011-0332"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0001" ref_id="CVE-2011-0001"/>
        <description>[1.0.4-3.1]
- fix the buffer overflow bug before iscsi login (CVE-2011-0001)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:57.078-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:02.429-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:51.936-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:56:45.722-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:56:45.722-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="scsi-target-utils is earlier than 0:1.0.8-0.el5_6.1" test_ref="oval:org.mitre.oval:tst:133751"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="scsi-target-utils is earlier than 0:1.0.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:134176"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27750" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0705 -- openoffice.org security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0705.html" ref_id="ELSA-2012-0705"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1149" ref_id="CVE-2012-1149"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2334" ref_id="CVE-2012-2334"/>
        <description>[1:3.2.1-19.6.0.1.el6_2.7]
- Replaced RedHat colors with Oracle colors, OOO_VENDOR with Oracle Corp.,
  and the filename redhat.soc with oracle.soc in specfile

[1:3.2.1-19.6.7]
- Resolves: CVE-2012-2334 Integer overflow leading to buffer overflow by
  processing invalid Escher graphics records length in the Powerpoint
  documents

[1:3.2.1-19.6.6]
- Resolves: CVE-2012-1149 Integer overflows, leading to heap-buffer
  overflows in JPEG, PNG and BMP reader implementations</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:21.624-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:01.417-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:51.393-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:39:07.697-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:39:07.697-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openoffice.org is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131814"/>
          <criterion comment="autocorr-af is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131675"/>
          <criterion comment="autocorr-bg is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131999"/>
          <criterion comment="autocorr-cs is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131316"/>
          <criterion comment="autocorr-da is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132018"/>
          <criterion comment="autocorr-de is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131693"/>
          <criterion comment="autocorr-en is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131417"/>
          <criterion comment="autocorr-es is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131026"/>
          <criterion comment="autocorr-eu is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131034"/>
          <criterion comment="autocorr-fa is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131937"/>
          <criterion comment="autocorr-fi is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131189"/>
          <criterion comment="autocorr-fr is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132011"/>
          <criterion comment="autocorr-ga is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131053"/>
          <criterion comment="autocorr-hu is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132026"/>
          <criterion comment="autocorr-it is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131587"/>
          <criterion comment="autocorr-ja is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131102"/>
          <criterion comment="autocorr-ko is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132097"/>
          <criterion comment="autocorr-lb is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131993"/>
          <criterion comment="autocorr-lt is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131971"/>
          <criterion comment="autocorr-mn is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131910"/>
          <criterion comment="autocorr-nl is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131434"/>
          <criterion comment="autocorr-pl is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131730"/>
          <criterion comment="autocorr-pt is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132083"/>
          <criterion comment="autocorr-ru is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132053"/>
          <criterion comment="autocorr-sk is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132023"/>
          <criterion comment="autocorr-sl is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131731"/>
          <criterion comment="autocorr-sv is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132092"/>
          <criterion comment="autocorr-tr is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131800"/>
          <criterion comment="autocorr-vi is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132028"/>
          <criterion comment="autocorr-zh is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131955"/>
          <criterion comment="broffice.org-base is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131906"/>
          <criterion comment="broffice.org-brand is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131951"/>
          <criterion comment="broffice.org-calc is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132089"/>
          <criterion comment="broffice.org-draw is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131794"/>
          <criterion comment="broffice.org-impress is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132093"/>
          <criterion comment="broffice.org-math is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131688"/>
          <criterion comment="broffice.org-writer is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132024"/>
          <criterion comment="openoffice.org-base is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132082"/>
          <criterion comment="openoffice.org-base-core is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131891"/>
          <criterion comment="openoffice.org-brand is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132008"/>
          <criterion comment="openoffice.org-bsh is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131990"/>
          <criterion comment="openoffice.org-calc is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131944"/>
          <criterion comment="openoffice.org-calc-core is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131964"/>
          <criterion comment="openoffice.org-core is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131695"/>
          <criterion comment="openoffice.org-devel is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132020"/>
          <criterion comment="openoffice.org-draw is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131995"/>
          <criterion comment="openoffice.org-draw-core is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131671"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132063"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131907"/>
          <criterion comment="openoffice.org-headless is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131953"/>
          <criterion comment="openoffice.org-impress is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131920"/>
          <criterion comment="openoffice.org-impress-core is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132059"/>
          <criterion comment="openoffice.org-javafilter is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131103"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132069"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131542"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131831"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132102"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131862"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131793"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131861"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131786"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132086"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131983"/>
          <criterion comment="openoffice.org-langpack-dz is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131808"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131929"/>
          <criterion comment="openoffice.org-langpack-en is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131768"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132078"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131658"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132077"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132054"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131915"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131806"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132021"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131902"/>
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131792"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131114"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132071"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132002"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132056"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131871"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131494"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132070"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131838"/>
          <criterion comment="openoffice.org-langpack-mai_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131231"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131818"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131947"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132047"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131744"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131939"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132090"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131899"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132051"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131884"/>
          <criterion comment="openoffice.org-langpack-pa is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131924"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131895"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131943"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131992"/>
          <criterion comment="openoffice.org-langpack-ro is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131819"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131258"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131970"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132034"/>
          <criterion comment="openoffice.org-langpack-sr is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132108"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131888"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131771"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132050"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131998"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131994"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132015"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131922"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132096"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131153"/>
          <criterion comment="openoffice.org-langpack-uk is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131909"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132012"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131847"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131972"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132060"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132025"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132151"/>
          <criterion comment="openoffice.org-math is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132046"/>
          <criterion comment="openoffice.org-math-core is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131883"/>
          <criterion comment="openoffice.org-ogltrans is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131637"/>
          <criterion comment="openoffice.org-opensymbol-fonts is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131896"/>
          <criterion comment="openoffice.org-pdfimport is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132022"/>
          <criterion comment="openoffice.org-presentation-minimizer is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131874"/>
          <criterion comment="openoffice.org-presenter-screen is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132143"/>
          <criterion comment="openoffice.org-pyuno is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131155"/>
          <criterion comment="openoffice.org-report-builder is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132065"/>
          <criterion comment="openoffice.org-rhino is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132149"/>
          <criterion comment="openoffice.org-sdk is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132066"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132036"/>
          <criterion comment="openoffice.org-testtools is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131885"/>
          <criterion comment="openoffice.org-ure is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:131256"/>
          <criterion comment="openoffice.org-wiki-publisher is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132111"/>
          <criterion comment="openoffice.org-writer is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132049"/>
          <criterion comment="openoffice.org-writer-core is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132087"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 0:3.2.1-19.6.0.1.el6_2.7" test_ref="oval:org.mitre.oval:tst:132127"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27746" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2043 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2043.html" ref_id="ELSA-2012-2043"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2133" ref_id="CVE-2012-2133"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3400" ref_id="CVE-2012-3400"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3511" ref_id="CVE-2012-3511"/>
        <description>[2.6.39-300.17.2]

- hugepages: fix use after free bug in 'quota' handling [Orabug: 15845276] {CVE-2012-2133}

- udf: Fortify loading of sparing table [Orabug: 15845302] {CVE-2012-3400}

- udf: Avoid run away loop when partition table length is corrupt [Orabug: 15845302] {CVE-2012-3400}

- mm: Hold a file reference in madvise_remove [Orabug: 15846025] {CVE-2012-3511}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:35.299-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:00.629-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:50.776-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130837"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130821"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130924"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129995"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130529"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129988"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130693"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130986"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130904"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130627"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130935"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130969"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27745" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0426 -- openssl security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0426.html" ref_id="ELSA-2012-0426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0884" ref_id="CVE-2012-0884"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1165" ref_id="CVE-2012-1165"/>
        <description>[1.0.0-20.3]

- fix problem with the SGC restart patch that might terminate handshake

  incorrectly

- fix for CVE-2012-0884 - MMA weakness in CMS and PKCS#7 code (#802725)

- fix for CVE-2012-1165 - NULL read dereference on bad MIME headers (#802489)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:17.279-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:06:00.298-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:50.629-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:01:33.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:01:33.577-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:132481"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:132426"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:132361"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:132571"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:132351"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:132353"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:132226"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27740" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1211 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1211.html" ref_id="ELSA-2012-1211"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1970" ref_id="CVE-2012-1970"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1972" ref_id="CVE-2012-1972"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1973" ref_id="CVE-2012-1973"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1974" ref_id="CVE-2012-1974"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1975" ref_id="CVE-2012-1975"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1976" ref_id="CVE-2012-1976"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3956" ref_id="CVE-2012-3956"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3957" ref_id="CVE-2012-3957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3958" ref_id="CVE-2012-3958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3959" ref_id="CVE-2012-3959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3960" ref_id="CVE-2012-3960"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3961" ref_id="CVE-2012-3961"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3962" ref_id="CVE-2012-3962"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3963" ref_id="CVE-2012-3963"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3964" ref_id="CVE-2012-3964"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3966" ref_id="CVE-2012-3966"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3967" ref_id="CVE-2012-3967"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3968" ref_id="CVE-2012-3968"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3969" ref_id="CVE-2012-3969"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3970" ref_id="CVE-2012-3970"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3972" ref_id="CVE-2012-3972"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3978" ref_id="CVE-2012-3978"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3980" ref_id="CVE-2012-3980"/>
        <description>[10.0.7-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[10.0.7-1]
- Update to 10.0.7 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:32.209-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:56.855-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:49.242-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:52:43.798-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:52:43.798-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:10.0.7-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130371"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27739" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1255 -- libexif security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libexif</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1255.html" ref_id="ELSA-2012-1255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2812" ref_id="CVE-2012-2812"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2813" ref_id="CVE-2012-2813"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2814" ref_id="CVE-2012-2814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2836" ref_id="CVE-2012-2836"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2837" ref_id="CVE-2012-2837"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2840" ref_id="CVE-2012-2840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2841" ref_id="CVE-2012-2841"/>
        <description>[0.6.21-5]
- Update to version 0.6.21 fixing many bugs and CVEs
- Remove upstreamed patches
- Resolves: #839915</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:20.346-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:55.940-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:48.856-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:05:29.550-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:05:29.550-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libexif is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:131242"/>
            <criterion comment="libexif-devel is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:131345"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libexif is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:131214"/>
            <criterion comment="libexif-devel is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:130926"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27738" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1948 -- nss, nss-util, and nss-softokn security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1948.html" ref_id="ELSA-2014-1948"/>
        <description>[3.16.2.3-2.0.1.el7_0]
- Added nss-vendor.patch to change vendor

[3.16.2.3-2]
- Restore patch for certutil man page
- supply missing options descriptions
- Resolves: Bug 1165525 - Upgrade to NSS 3.16.2.3 for Firefox 31.3</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:31.805-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:13.578-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:14.373-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:136045"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:136044"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135871"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135923"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135884"/>
            <criterion comment="nss-util is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:135903"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135849"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135800"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:135863"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:136041"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:135475"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135518"/>
            <criterion comment="nss-softokn is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135943"/>
            <criterion comment="nss-util is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135336"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135683"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135765"/>
            <criterion comment="nss-softokn-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135292"/>
            <criterion comment="nss-softokn-freebl is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135697"/>
            <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136043"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135919"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:135947"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136002"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27736" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0560 -- sssd security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0560.html" ref_id="ELSA-2011-0560"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4341" ref_id="CVE-2010-4341"/>
        <description>[1.5.1-34]
- Resolves: rhbz#701700 - sssd client libraries use select() but should use
-                         poll() instead

[1.5.1-33]
- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password
- Fix segfault in TGT renewal

[1.5.1-32]
- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password
- Fix typo causing build breakage

[1.5.1-31]
- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password

[1.5.1-30]
- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users

[1.5.1-29]
- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:23.273-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:54.917-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:48.382-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:46:17.870-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:46:17.870-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="sssd is earlier than 0:1.5.1-34.el6" test_ref="oval:org.mitre.oval:tst:133417"/>
          <criterion comment="sssd-client is earlier than 0:1.5.1-34.el6" test_ref="oval:org.mitre.oval:tst:133794"/>
          <criterion comment="sssd-tools is earlier than 0:1.5.1-34.el6" test_ref="oval:org.mitre.oval:tst:133505"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27735" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2026 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2026.html" ref_id="ELSA-2012-2026"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1083" ref_id="CVE-2011-1083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2745" ref_id="CVE-2012-2745"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3375" ref_id="CVE-2012-3375"/>
        <description>[2.6.32-300.29.2] - epoll: epoll_wait() should not use timespec_add_ns() (Eric
          Dumazet) - epoll: clear the tfile_check_list on -ELOOP (Joe Jin) {CVE-2012-3375} - Don't
          limit non-nested epoll paths (Jason Baron) - epoll: kabi fixups for epoll limit wakeup
          paths (Joe Jin) {CVE-2011-1083} - epoll: limit paths (Jason Baron) {CVE-2011-1083} -
          eventpoll: fix comment typo 'evenpoll' (Paul Bolle) - epoll: fix compiler warning and
          optimize the non-blocking path (Shawn Bohrer) - epoll: move ready event check into proper
          inline (Davide Libenzi) - epoll: make epoll_wait() use the hrtimer range feature (Shawn
          Bohrer) - select: rename estimate_accuracy() to select_estimate_accuracy() (Andrew Morton)
          - cred: copy_process() should clear child->replacement_session_keyring (Oleg Nesterov)
          {CVE-2012-2745}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:37.842-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:54.689-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:48.200-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:130681 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:41.770-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:32.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131605"/>
            <criterion comment="mlnx_en-2.6.32-300.29.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131448"/>
            <criterion comment="ofa-2.6.32-300.29.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131598"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131613"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131264"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131583"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131215"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131509"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131489"/>
            <criterion comment="mlnx_en-2.6.32-300.29.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130681"/>
            <criterion comment="ofa-2.6.32-300.29.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131453"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:130732"/>
            <criterion comment="mlnx_en-2.6.32-300.29.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131578"/>
            <criterion comment="ofa-2.6.32-300.29.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131478"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:130987"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131375"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131608"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131246"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131326"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131611"/>
            <criterion comment="mlnx_en-2.6.32-300.29.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131572"/>
            <criterion comment="ofa-2.6.32-300.29.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131569"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27734" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0928 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0928.html" ref_id="ELSA-2011-0928"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1767" ref_id="CVE-2011-1767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1768" ref_id="CVE-2011-1768"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2479" ref_id="CVE-2011-2479"/>
        <description>[2.6.32-131.6.1.el6]
- [audit] ia32entry.S sign extend error codes when calling 64 bit code (Eric Paris) [713831 703935]
- [audit] push audit success and retcode into arch ptrace.h (Eric Paris) [713831 703935]
- [x86] intel-iommu: Flush unmaps at domain_exit (Alex Williamson) [713458 705441]
- [x86] intel-iommu: Only unlink device domains from iommu (Alex Williamson) [713458 705441]
- [virt] x86: Mask out unsupported CPUID features if running on xen (Igor Mammedov) [711546 703055]
- [block] fix accounting bug on cross partition merges (Jerome Marchand) [682989 669363]
- [net] vlan: remove multiqueue ability from vlan device (Neil Horman) [713494 703245]
- [net] Fix netif_set_real_num_tx_queues (Neil Horman) [713492 702742]
- [scsi] mpt2sas: move event handling of MPT2SAS_TURN_ON_FAULT_LED in process context (Tomas Henzl) [714190 701951]
- [mm] thp: simple fix for /dev/zero THP mprotect bug (Andrea Arcangeli) [714762 690444]

[2.6.32-131.5.1.el6]
- [kernel] cgroupfs: use init_cred when populating new cgroupfs mount (Eric Paris) [713135 700538]
- [netdrv] ixgbe: adding FdirMode module option (Andy Gospodarek) [711550 707287]
- [crypto] testmgr: add xts-aes-256 self-test (Jarod Wilson) [711548 706167]
- [fs] ext3: Fix lost extented attributes for inode with ino == 11 (Eric Sandeen) [712413 662666]
- [mm] Prevent Disk IO throughput degradation due to memory allocation stalls (Larry Woodman) [711540 679526]
- [net] sock: adjust prot->obj_size always (Jiri Pirko) [709381 704231]
- [fs] GFS2: resource group bitmap corruption resulting in panics and withdraws (Robert S Peterson) [711528 702057]
- [x86] kprobes: Disable irqs during optimized callback (Jiri Olsa) [711545 699865]
- [mm] slab, kmemleak: pass the correct pointer to kmemleak_erase() (Steve Best) [712414 698023]
- [net] fix netns vs proto registration ordering (Wade Mealing) [702305 702306] {CVE-2011-1767 CVE-2011-1768}
- [ppc] Fix oops if scan_dispatch_log is called too early (Steve Best) [711524 696777]
- [virt] i8259: initialize isr_ack (Avi Kivity) [711520 670765]
- [virt] VMX: Save and restore tr selector across mode switches (Gleb Natapov) [711535 693894]
- [virt] VMX: update live TR selector if it changes in real mode (Gleb Natapov) [711535 693894]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:24.003-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:54.226-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:47.935-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:45:24.376-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:45:24.376-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:133239"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:133483"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:133711"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:133738"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:133669"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:133659"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:133695"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:133357"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27733" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0973 -- nss, nss-util, and nspr security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
          <product>nspr-devel</product>
          <product>nss-devel</product>
          <product>nss-pkcs11-devel</product>
          <product>nss-sysinit</product>
          <product>nss-tools</product>
          <product>nss-util-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0973.html" ref_id="ELSA-2012-0973"/>
        <description>nspr
[4.9-1]
- Resolves: rhbz#799193 - Update to 4.9

nss
[3.13.3-6.0.1.el6]
- Added nss-vendor.patch to change vendor
- Use blank image instead of clean.gif in tar ball

[3.13.3-6]
- Resolves: #rhbz#805232 PEM module may attempt to free uninitialized pointer

[3.13.3-5]
- Resolves: rhbz#717913 - [PEM] various flaws detected by Coverity
- Require nss-util 3.13.3

[3.13.3-4]
- Resolves: rhbz#772628 nss_Init leaks memory

[3.13.3-3]
- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name
- Use completed patch per code review

[3.13.3-2]
- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name
- Resolves: rhbz#768669 - PEM unregistered callback causes SIGSEGV

[3.13.3-1]
- Update to 3.13.3
- Resolves: rhbz#798539 - Distrust MITM subCAs issued by TrustWave
- Remove builtins-nssckbi_1_88_rtm.patch which the rebase obsoletes

nss-util
[3.13.3-2]
- Resolves: rhbz#799192 - Update to 3.13.3
- Update minimum nspr version for Requires and BuildRequires to 4.9
- Fix version/release in changelog to match the Version and Release tags, now 3.13.3-2

[3.13.1-5]
- Resolves: rhbz#799192 - Update to 3.13.3</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:34.405-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:54.084-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:47.815-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:38:07.271-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:38:07.271-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.9-1.el6" test_ref="oval:org.mitre.oval:tst:131820"/>
          <criterion comment="nss is earlier than 0:3.13.3-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131705"/>
          <criterion comment="nss-util is earlier than 0:3.13.3-2.el6" test_ref="oval:org.mitre.oval:tst:131815"/>
          <criterion comment="nspr-devel is earlier than 0:4.9-1.el6" test_ref="oval:org.mitre.oval:tst:131640"/>
          <criterion comment="nss-devel is earlier than 0:3.13.3-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131649"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.3-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131743"/>
          <criterion comment="nss-sysinit is earlier than 0:3.13.3-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131517"/>
          <criterion comment="nss-tools is earlier than 0:3.13.3-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131501"/>
          <criterion comment="nss-util-devel is earlier than 0:3.13.3-2.el6" test_ref="oval:org.mitre.oval:tst:131406"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27727" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1256 -- ghostscript security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1256.html" ref_id="ELSA-2012-1256"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4405" ref_id="CVE-2012-4405"/>
        <description>[8.70-14:.1]
- Added inputChan lower-bounds checking to icclib (bug #854227,
  CVE-2012-4405).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:16.281-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:53.186-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:47.192-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:06:04.288-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:06:04.288-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:131325"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:131199"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:131226"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130691"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130899"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:131148"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130722"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27724" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1068 -- openjpeg security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openjpeg</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1068.html" ref_id="ELSA-2012-1068"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5030" ref_id="CVE-2009-5030"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3358" ref_id="CVE-2012-3358"/>
        <description>[1.3-8]
- Apply patches for CVE-2009-5030, CVE-2012-3358
Resolves: #831561
- Include -DCMAKE_INSTALL_LIBDIR in cmake call; fixes FTBFS with recent
  versions of cmake</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:40.575-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:52.542-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:46.780-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:36:15.355-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:36:15.355-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openjpeg is earlier than 0:1.3-8.el6_3" test_ref="oval:org.mitre.oval:tst:131497"/>
          <criterion comment="openjpeg-devel is earlier than 0:1.3-8.el6_3" test_ref="oval:org.mitre.oval:tst:131630"/>
          <criterion comment="openjpeg-libs is earlier than 0:1.3-8.el6_3" test_ref="oval:org.mitre.oval:tst:131440"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27721" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1234 -- qemu-kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1234.html" ref_id="ELSA-2012-1234"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3515" ref_id="CVE-2012-3515"/>
        <description>[0.12.1.2-2.295.el6_3.2]
- kvm-console-bounds-check-whenever-changing-the-cursor-du.patch [bz#851257
- Resolves: bz#851257
  (EMBARGOED CVE-2012-3515 qemu/kvm: VT100 emulation vulnerability [rhel-6.3.z])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:30.074-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:51.055-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:46.087-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:08:07.407-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:08:07.407-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:131313"/>
          <criterion comment="qemu-guest-agent is earlier than 0:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:131190"/>
          <criterion comment="qemu-img is earlier than 0:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:130955"/>
          <criterion comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:130544"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27718" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1037 -- postgresql and postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1037.html" ref_id="ELSA-2012-1037"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2143" ref_id="CVE-2012-2143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2655" ref_id="CVE-2012-2655"/>
        <description>[8.4.12-1]
- Update to PostgreSQL 8.4.12, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-12.html
  including the fixes for CVE-2012-2143, CVE-2012-2655
Resolves: #830723

[8.4.11-2]
- Add patches for CVE-2012-2143, CVE-2012-2655
Resolves: #830723

[8.4.11-1]
- Update to PostgreSQL 8.4.11, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-11.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-10.html
  including the fixes for CVE-2012-0866, CVE-2012-0867, CVE-2012-0868
Resolves: #812077</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:32.197-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:50.270-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:45.503-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:01:54.008-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:01:54.008-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131842"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131856"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131552"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131236"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131492"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131830"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131855"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:130981"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131641"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131752"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131560"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:131721"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131835"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131706"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131525"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131790"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:130912"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:130943"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131672"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131844"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131513"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:131859"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27715" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0546 -- php security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0546.html" ref_id="ELSA-2012-0546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1823" ref_id="CVE-2012-1823"/>
        <description>[5.3.3-3.8]
- correct detection of = in CVE-2012-1823 fix (#818607)

[5.3.3-3.7]
- add security fix for CVE-2012-1823 (#818607)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:05.294-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:49.451-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:44.892-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:25:10.626-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:25:10.626-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132336"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132308"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132365"/>
            <criterion comment="php-common is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132390"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132141"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132357"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132229"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132107"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:131419"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132292"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132252"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132324"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132228"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132076"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132199"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132331"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132348"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132342"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:132257"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132406"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132084"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132073"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132219"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132238"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132297"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:131919"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132317"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:131638"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:131956"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:131942"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132277"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132165"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132374"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132281"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132211"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132352"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132286"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132146"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132067"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132405"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132177"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132196"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132246"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132276"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:132204"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27714" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0388 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0388.html" ref_id="ELSA-2012-0388"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0451" ref_id="CVE-2012-0451"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0455" ref_id="CVE-2012-0455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0456" ref_id="CVE-2012-0456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0457" ref_id="CVE-2012-0457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0458" ref_id="CVE-2012-0458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0459" ref_id="CVE-2012-0459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0460" ref_id="CVE-2012-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0461" ref_id="CVE-2012-0461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0462" ref_id="CVE-2012-0462"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0464" ref_id="CVE-2012-0464"/>
        <description>[10.0.3-1.0.1.el6_2]
- Replaced thunderbird-redhat-default-prefs.js with
  thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[10.0.3-1]
- Update to 10.0.3 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:13.326-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:48.512-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:44.403-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:06:03.240-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:06:03.240-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:10.0.3-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132551"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27712" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1202 -- libvirt security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1202.html" ref_id="ELSA-2012-1202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3445" ref_id="CVE-2012-3445"/>
        <description>[libvirt-0.9.10-21.0.1.el6_3.4]
- Replace docs/et.png in tarball with blank image

[libvirt-0.9.10-21.el6_3.4]
- daemon: Fix crash in virTypedParameterArrayClear (rhbz#844735)
- remote: Fix locking in stream APIs (rhbz#847946)
- Using virOnce for global initialization is desirable (rhbz#847959)
- json: Fix interface locale dependency (rhbz#847959)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:27.174-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:48.174-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:44.115-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:59:17.333-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:59:17.333-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.9.10-21.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:131106"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:131001"/>
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130930"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130694"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27710" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1088 -- systemtap security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1088.html" ref_id="ELSA-2011-1088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2502" ref_id="CVE-2011-2502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2503" ref_id="CVE-2011-2503"/>
        <description>[1.4.6.0.1.el6_1.2]
- remove doc/SystemTap_Beginners_Guide/en-US in tarball
- comment bz683569.patch in specfile

[1.4-6.2]
- bz716476 (patch)
- bz716489 (patch)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:29.764-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:47.856-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:43.885-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:08:10.883-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:08:10.883-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="systemtap is earlier than 0:1.4-6.0.1.el6_1.2" test_ref="oval:org.mitre.oval:tst:133326"/>
          <criterion comment="systemtap-client is earlier than 0:1.4-6.0.1.el6_1.2" test_ref="oval:org.mitre.oval:tst:133655"/>
          <criterion comment="systemtap-grapher is earlier than 0:1.4-6.0.1.el6_1.2" test_ref="oval:org.mitre.oval:tst:133731"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.4-6.0.1.el6_1.2" test_ref="oval:org.mitre.oval:tst:133682"/>
          <criterion comment="systemtap-runtime is earlier than 0:1.4-6.0.1.el6_1.2" test_ref="oval:org.mitre.oval:tst:133614"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.4-6.0.1.el6_1.2" test_ref="oval:org.mitre.oval:tst:133706"/>
          <criterion comment="systemtap-server is earlier than 0:1.4-6.0.1.el6_1.2" test_ref="oval:org.mitre.oval:tst:133719"/>
          <criterion comment="systemtap-testsuite is earlier than 0:1.4-6.0.1.el6_1.2" test_ref="oval:org.mitre.oval:tst:133431"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27709" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1386 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1386.html" ref_id="ELSA-2012-1386"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3216" ref_id="CVE-2012-3216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4416" ref_id="CVE-2012-4416"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5068" ref_id="CVE-2012-5068"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5069" ref_id="CVE-2012-5069"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5071" ref_id="CVE-2012-5071"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5072" ref_id="CVE-2012-5072"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5073" ref_id="CVE-2012-5073"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5075" ref_id="CVE-2012-5075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5077" ref_id="CVE-2012-5077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5079" ref_id="CVE-2012-5079"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5081" ref_id="CVE-2012-5081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5084" ref_id="CVE-2012-5084"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5085" ref_id="CVE-2012-5085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5086" ref_id="CVE-2012-5086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5089" ref_id="CVE-2012-5089"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5070" ref_id="CVE-2012-5070"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5074" ref_id="CVE-2012-5074"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5076" ref_id="CVE-2012-5076"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5087" ref_id="CVE-2012-5087"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5088" ref_id="CVE-2012-5088"/>
        <description>[1.7.0.9-2.3.3.0.1.el6_3.1]
- Update DISTRO_NAME in specfile

[1.7.0.9-2.3.3.el6.1]
- Changed permissions of sa-jdi.jar to correct 644
- Resolves: rhbz#865050

[1.7.0.9-2.3.3.el6]
- Updated to 2.3.3
- Updated java-1.7.0-openjdk-java-access-bridge-security.patch
- Resolves rhbz#s 856124, 865346, 865348, 865350, 865352, 865354, 865357,
  865359, 865363, 865365, 865370, 865428, 865471, 865434, 865511, 865514,
  865519, 865531, 865541, 865568

[1.7.0.5-2.3.2.el6.1]
- Cleanup before security release
- Updated to latest IcedTea7-forest 2.3
- Resolves: rhbz#852299

[1.7.0.5-2.2.1.1.el6.4]
- Cleanup before security release
- Removed patches:
   patch 1001 sec-webrevs-openjdk7-29_aug_2012-7162473.patch
   patch 1002 sec-webrevs-openjdk7-29_aug_2012-7162476.patch
   patch 1003 sec-webrevs-openjdk7-29_aug_2012-7163201.patch
   patch 1004 sec-webrevs-openjdk7-29_aug_2012-7194567.patch
   patch 1005 sec-webrevs-openjdk7-29_aug_2012-78e01a6ca8d3.patch
- Resolves: rhbz#852299</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:17.340-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:45.751-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:42.803-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:32:54.003-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:32:54.003-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.3.0.1.el6_3.1" test_ref="oval:org.mitre.oval:tst:131109"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.3.0.1.el6_3.1" test_ref="oval:org.mitre.oval:tst:130905"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.3.0.1.el6_3.1" test_ref="oval:org.mitre.oval:tst:131090"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.3.0.1.el6_3.1" test_ref="oval:org.mitre.oval:tst:130712"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.3.0.1.el6_3.1" test_ref="oval:org.mitre.oval:tst:130420"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27708" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1350 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1350.html" ref_id="ELSA-2011-1350"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1160" ref_id="CVE-2011-1160"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1745" ref_id="CVE-2011-1745"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1746" ref_id="CVE-2011-1746"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1833" ref_id="CVE-2011-1833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2022" ref_id="CVE-2011-2022"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2484" ref_id="CVE-2011-2484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2496" ref_id="CVE-2011-2496"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2521" ref_id="CVE-2011-2521"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2723" ref_id="CVE-2011-2723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2898" ref_id="CVE-2011-2898"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2918" ref_id="CVE-2011-2918"/>
        <description>[2.6.32-131.17.1.el6]
- Revert: [net] ipv6: make fragment identifications less predictable (Jiri Pirko) [723432 723433] {CVE-2011-2699}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:25.763-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:44.472-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:42.361-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:03:53.521-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:03:53.521-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:133176"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:133419"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:133333"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:133359"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:133164"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:133398"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:132770"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:133196"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27706" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1085 -- freetype security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1085.html" ref_id="ELSA-2011-1085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0226" ref_id="CVE-2011-0226"/>
        <description>[2.3.11-6.el6_1.6]
- A little change in configure part
- Resolves: #723467

[2.3.11-6.el6_1.5]
- Use -fno-strict-aliasing instead of __attribute__((__may_alias__))
- Resolves: #723467

[2.3.11-6.el6_1.4]
- Allow FT_Glyph to alias (to pass Rpmdiff)
- Resolves: #723467

[2.3.11-6.el6_1.3]
- Add freetype-2.3.11-CVE-2011-0226.patch
    (Add better argument check for 'callothersubr'.)
    - based on patches by Werner Lemberg,
      Alexei Podtelezhnikov and Matthias Drochner
- Resolves: #723467</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:45.656-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:44.260-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:42.264-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:46:01.349-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:46:01.349-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.6" test_ref="oval:org.mitre.oval:tst:133420"/>
          <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.6" test_ref="oval:org.mitre.oval:tst:133460"/>
          <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.6" test_ref="oval:org.mitre.oval:tst:133680"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27700" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0324 -- logwatch security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>logwatch</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0324.html" ref_id="ELSA-2011-0324"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1018" ref_id="CVE-2011-1018"/>
        <description>[7.3.6-49]
- Added fix for CVE-2011-1018: Privilege escalation due improper
  sanitization of special characters in log file names
  Resolves: #680304</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:49.632-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:42.619-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:41.412-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:35:05.184-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:35:05.184-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="logwatch is earlier than 0:7.3-9.el5_6" test_ref="oval:org.mitre.oval:tst:134126"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="logwatch is earlier than 0:7.3.6-49.el6" test_ref="oval:org.mitre.oval:tst:134095"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27699" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2022 -- Unbreakable Enterprise kernel security and bugfix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2022.html" ref_id="ELSA-2012-2022"/>
        <description>[2.6.39-200.24.1.el5uek]
- Revert 'Add Oracle VM guest messaging driver' (Guru Anbalagane) [Orabug: 14233627}

[2.6.39-200.23.1.el5uek]
- SPEC: add block/net modules to list used by installer (Guru Anbalagane)
  [Orabug: 14224837]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:21.059-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:42.448-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:41.185-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131185"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131657"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131441"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131411"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131618"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:131260"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131622"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131656"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131328"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131643"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131734"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:131681"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27698" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2014 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2014.html" ref_id="ELSA-2012-2014"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4086" ref_id="CVE-2011-4086"/>
        <description>kernel-uek: [2.6.32-300.25.1.el6uek] - jbd2: clear BH_Delay &amp; BH_Unwritten
          in journal_unmap_buffer (Eric Sandeen) [Bugdb: 13871] {CVE-2011-4086}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:06.149-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:42.213-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:40.995-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36392 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:37.020-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:30.543-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:132188"/>
            <criterion comment="mlnx_en-2.6.32-300.25.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131784"/>
            <criterion comment="ofa-2.6.32-300.25.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:132232"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:131595"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:131412"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:132044"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:131270"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:132161"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.25.1.el5uek" test_ref="oval:org.mitre.oval:tst:131701"/>
            <criterion comment="mlnx_en-2.6.32-300.25.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132248"/>
            <criterion comment="ofa-2.6.32-300.25.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131776"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132095"/>
            <criterion comment="mlnx_en-2.6.32-300.25.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132131"/>
            <criterion comment="ofa-2.6.32-300.25.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:131496"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132031"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:131809"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:131867"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132269"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132205"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.25.1.el6uek" test_ref="oval:org.mitre.oval:tst:132118"/>
            <criterion comment="mlnx_en-2.6.32-300.25.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132201"/>
            <criterion comment="ofa-2.6.32-300.25.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132224"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27697" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1350 -- firefox security and bug fix update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1350.html" ref_id="ELSA-2012-1350"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1956" ref_id="CVE-2012-1956"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3982" ref_id="CVE-2012-3982"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3986" ref_id="CVE-2012-3986"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3988" ref_id="CVE-2012-3988"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3990" ref_id="CVE-2012-3990"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3991" ref_id="CVE-2012-3991"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3992" ref_id="CVE-2012-3992"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3993" ref_id="CVE-2012-3993"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3994" ref_id="CVE-2012-3994"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3995" ref_id="CVE-2012-3995"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4179" ref_id="CVE-2012-4179"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4180" ref_id="CVE-2012-4180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4181" ref_id="CVE-2012-4181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4182" ref_id="CVE-2012-4182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4183" ref_id="CVE-2012-4183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4184" ref_id="CVE-2012-4184"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4185" ref_id="CVE-2012-4185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4186" ref_id="CVE-2012-4186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4187" ref_id="CVE-2012-4187"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4188" ref_id="CVE-2012-4188"/>
        <description>firefox
[10.0.8-1.0.2.el6_3]
- Updated firefox-oracle-default-prefs.js based on latest firefox-redhat-default-prefs.js

[10.0.8-1.0.1.el6_3]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.8-1]
- Update to 10.0.8 ESR

xulrunner
[10.0.8-1.0.1.el6_3]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.8-1]
- Update to 10.0.8 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:09.044-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:42.024-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:40.828-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:31:18.065-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:31:18.065-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.8-1.0.2.el5_8" test_ref="oval:org.mitre.oval:tst:130640"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130666"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130801"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.8-1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:131133"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130938"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130466"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27696" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1814 -- ipmitool security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ipmitool</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1814.html" ref_id="ELSA-2011-1814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4339" ref_id="CVE-2011-4339"/>
        <description>[1.8.11-12.1]
- fixed wrong permissions on ipmievd.pid (#756684)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:24.820-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:41.910-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:40.718-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:35:52.155-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:35:52.155-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="ipmitool is earlier than 0:1.8.11-12.el6_2.1" test_ref="oval:org.mitre.oval:tst:133071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27693" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0515 -- openchange security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>evolution-mapi</product>
          <product>openchange</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0515.html" ref_id="ELSA-2013-0515"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1182" ref_id="CVE-2012-1182"/>
        <description>A flaw was found in the Samba suite's Perl-based DCE/RPC IDL (PIDL)
compiler. As OpenChange uses code generated by PIDL, this could have
resulted in buffer overflows in the way OpenChange handles RPC calls. With
this update, the code has been generated with an updated version of PIDL to
correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:48.737-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:41.297-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:40.292-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:22:59.790-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:22:59.790-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="evolution-mapi is earlier than 0:0.28.3-12.el6" test_ref="oval:org.mitre.oval:tst:130109"/>
          <criterion comment="openchange is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:130225"/>
          <criterion comment="evolution-mapi-devel is earlier than 0:0.28.3-12.el6" test_ref="oval:org.mitre.oval:tst:129954"/>
          <criterion comment="openchange-client is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:130032"/>
          <criterion comment="openchange-devel is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:129333"/>
          <criterion comment="openchange-devel-docs is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:130146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27692" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0568 -- eclipse security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>eclipse</product>
          <product>eclipse-birt</product>
          <product>eclipse-callgraph</product>
          <product>eclipse-cdt</product>
          <product>eclipse-changelog</product>
          <product>eclipse-dtp</product>
          <product>eclipse-emf</product>
          <product>eclipse-gef</product>
          <product>eclipse-linuxprofilingframework</product>
          <product>eclipse-mylyn</product>
          <product>eclipse-oprofile</product>
          <product>eclipse-rse</product>
          <product>eclipse-valgrind</product>
          <product>icu4j</product>
          <product>jetty-eclipse</product>
          <product>objectweb-asm</product>
          <product>sat4j</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0568.html" ref_id="ELSA-2011-0568"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4647" ref_id="CVE-2010-4647"/>
        <description>A cross-site scripting (XSS) flaw was found in the Eclipse Help Contents
web application. An attacker could use this flaw to perform a cross-site
scripting attack against victims by tricking them into visiting a
specially-crafted Eclipse Help URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:03.459-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:40.807-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:39.717-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:58:39.605-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:58:39.605-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="eclipse is earlier than 0:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:132974"/>
          <criterion comment="eclipse-birt is earlier than 0:2.6.0-1.1.el6" test_ref="oval:org.mitre.oval:tst:133124"/>
          <criterion comment="eclipse-callgraph is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:133316"/>
          <criterion comment="eclipse-cdt is earlier than 0:7.0.1-4.el6" test_ref="oval:org.mitre.oval:tst:133843"/>
          <criterion comment="eclipse-changelog is earlier than 0:2.7.0-1.el6" test_ref="oval:org.mitre.oval:tst:133891"/>
          <criterion comment="eclipse-dtp is earlier than 0:1.8.1-1.1.el6" test_ref="oval:org.mitre.oval:tst:133260"/>
          <criterion comment="eclipse-emf is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:133921"/>
          <criterion comment="eclipse-gef is earlier than 0:3.6.1-3.el6" test_ref="oval:org.mitre.oval:tst:133876"/>
          <criterion comment="eclipse-linuxprofilingframework is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:133445"/>
          <criterion comment="eclipse-mylyn is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:133859"/>
          <criterion comment="eclipse-oprofile is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:133498"/>
          <criterion comment="eclipse-rse is earlier than 0:3.2-1.el6" test_ref="oval:org.mitre.oval:tst:133742"/>
          <criterion comment="eclipse-valgrind is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:133944"/>
          <criterion comment="icu4j is earlier than 0:4.2.1-5.el6" test_ref="oval:org.mitre.oval:tst:133748"/>
          <criterion comment="jetty-eclipse is earlier than 0:6.1.24-2.el6" test_ref="oval:org.mitre.oval:tst:133741"/>
          <criterion comment="objectweb-asm is earlier than 0:3.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:133966"/>
          <criterion comment="sat4j is earlier than 0:2.2.0-4.0.el6" test_ref="oval:org.mitre.oval:tst:133538"/>
          <criterion comment="eclipse-cdt-parsers is earlier than 0:7.0.1-4.el6" test_ref="oval:org.mitre.oval:tst:133632"/>
          <criterion comment="eclipse-cdt-sdk is earlier than 0:7.0.1-4.el6" test_ref="oval:org.mitre.oval:tst:133401"/>
          <criterion comment="eclipse-emf-examples is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:133799"/>
          <criterion comment="eclipse-emf-sdk is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:133872"/>
          <criterion comment="eclipse-emf-xsd is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:133963"/>
          <criterion comment="eclipse-emf-xsd-sdk is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:133228"/>
          <criterion comment="eclipse-gef-examples is earlier than 0:3.6.1-3.el6" test_ref="oval:org.mitre.oval:tst:133770"/>
          <criterion comment="eclipse-gef-sdk is earlier than 0:3.6.1-3.el6" test_ref="oval:org.mitre.oval:tst:133030"/>
          <criterion comment="eclipse-jdt is earlier than 0:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:133183"/>
          <criterion comment="eclipse-mylyn-cdt is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:133940"/>
          <criterion comment="eclipse-mylyn-java is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:133076"/>
          <criterion comment="eclipse-mylyn-pde is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:134072"/>
          <criterion comment="eclipse-mylyn-trac is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:133826"/>
          <criterion comment="eclipse-mylyn-webtasks is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:133649"/>
          <criterion comment="eclipse-mylyn-wikitext is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:133616"/>
          <criterion comment="eclipse-pde is earlier than 0:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:133854"/>
          <criterion comment="eclipse-platform is earlier than 0:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:133961"/>
          <criterion comment="eclipse-rcp is earlier than 0:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:133970"/>
          <criterion comment="eclipse-swt is earlier than 0:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:134076"/>
          <criterion comment="icu4j-eclipse is earlier than 0:4.2.1-5.el6" test_ref="oval:org.mitre.oval:tst:134043"/>
          <criterion comment="icu4j-javadoc is earlier than 0:4.2.1-5.el6" test_ref="oval:org.mitre.oval:tst:133707"/>
          <criterion comment="objectweb-asm-javadoc is earlier than 0:3.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:134035"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27690" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0558 -- perl security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0558.html" ref_id="ELSA-2011-0558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2761" ref_id="CVE-2010-2761"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4410" ref_id="CVE-2010-4410"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1487" ref_id="CVE-2011-1487"/>
        <description>[5.10.1-119]
- 692862 - lc launders tainted flag, CVE-2011-1487
- make SOURCE1 executable, because it missed +x in brew
- Resolves: rhbz#692862

[5.10.1-118]
- Correct perl-5.10.1-rt77352.patch
- Related: rhbz#640720

[5.10.1-117]
- 671352 CGI-3.51 security update
- Resolves: rhbz#671352

[5.10.1-116]
- require Digest::SHA 640716
- remove removal of NDBM 640729
- remove unsupported option fork from prove's documentation 609492
- Thread desctructor leaks 640720
- update threads to 1.82 (bugfixes releases) 626330
- remove unused patches from cvs
- Resolves: rhbz#640729, rhbz#640716, rhbz#609492, rhbz#640720, rhbz#626330</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:46.880-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:40.046-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:39.007-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:34:32.821-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:34:32.821-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="perl is earlier than 0:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:133909"/>
          <criterion comment="perl-Archive-Extract is earlier than 0:0.38-119.el6" test_ref="oval:org.mitre.oval:tst:133545"/>
          <criterion comment="perl-Archive-Tar is earlier than 0:1.58-119.el6" test_ref="oval:org.mitre.oval:tst:133456"/>
          <criterion comment="perl-CGI is earlier than 0:3.51-119.el6" test_ref="oval:org.mitre.oval:tst:133764"/>
          <criterion comment="perl-CPAN is earlier than 0:1.9402-119.el6" test_ref="oval:org.mitre.oval:tst:133411"/>
          <criterion comment="perl-CPANPLUS is earlier than 0:0.88-119.el6" test_ref="oval:org.mitre.oval:tst:133927"/>
          <criterion comment="perl-Compress-Raw-Zlib is earlier than 0:2.023-119.el6" test_ref="oval:org.mitre.oval:tst:133878"/>
          <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-119.el6" test_ref="oval:org.mitre.oval:tst:133463"/>
          <criterion comment="perl-Digest-SHA is earlier than 0:5.47-119.el6" test_ref="oval:org.mitre.oval:tst:133575"/>
          <criterion comment="perl-ExtUtils-CBuilder is earlier than 0:0.27-119.el6" test_ref="oval:org.mitre.oval:tst:133802"/>
          <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-119.el6" test_ref="oval:org.mitre.oval:tst:133692"/>
          <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-119.el6" test_ref="oval:org.mitre.oval:tst:133800"/>
          <criterion comment="perl-ExtUtils-ParseXS is earlier than 0:2.2003.0-119.el6" test_ref="oval:org.mitre.oval:tst:133712"/>
          <criterion comment="perl-File-Fetch is earlier than 0:0.26-119.el6" test_ref="oval:org.mitre.oval:tst:133797"/>
          <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-119.el6" test_ref="oval:org.mitre.oval:tst:133822"/>
          <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-119.el6" test_ref="oval:org.mitre.oval:tst:133576"/>
          <criterion comment="perl-IO-Zlib is earlier than 0:1.09-119.el6" test_ref="oval:org.mitre.oval:tst:133497"/>
          <criterion comment="perl-IPC-Cmd is earlier than 0:0.56-119.el6" test_ref="oval:org.mitre.oval:tst:133814"/>
          <criterion comment="perl-Locale-Maketext-Simple is earlier than 0:0.18-119.el6" test_ref="oval:org.mitre.oval:tst:133938"/>
          <criterion comment="perl-Log-Message is earlier than 0:0.02-119.el6" test_ref="oval:org.mitre.oval:tst:133269"/>
          <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-119.el6" test_ref="oval:org.mitre.oval:tst:133804"/>
          <criterion comment="perl-Module-Build is earlier than 0:0.3500-119.el6" test_ref="oval:org.mitre.oval:tst:133542"/>
          <criterion comment="perl-Module-CoreList is earlier than 0:2.18-119.el6" test_ref="oval:org.mitre.oval:tst:133894"/>
          <criterion comment="perl-Module-Load is earlier than 0:0.16-119.el6" test_ref="oval:org.mitre.oval:tst:133766"/>
          <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-119.el6" test_ref="oval:org.mitre.oval:tst:133263"/>
          <criterion comment="perl-Module-Loaded is earlier than 0:0.02-119.el6" test_ref="oval:org.mitre.oval:tst:133442"/>
          <criterion comment="perl-Module-Pluggable is earlier than 0:3.90-119.el6" test_ref="oval:org.mitre.oval:tst:133875"/>
          <criterion comment="perl-Object-Accessor is earlier than 0:0.34-119.el6" test_ref="oval:org.mitre.oval:tst:133716"/>
          <criterion comment="perl-Package-Constants is earlier than 0:0.02-119.el6" test_ref="oval:org.mitre.oval:tst:133737"/>
          <criterion comment="perl-Params-Check is earlier than 0:0.26-119.el6" test_ref="oval:org.mitre.oval:tst:133660"/>
          <criterion comment="perl-Parse-CPAN-Meta is earlier than 0:1.40-119.el6" test_ref="oval:org.mitre.oval:tst:133690"/>
          <criterion comment="perl-Pod-Escapes is earlier than 0:1.04-119.el6" test_ref="oval:org.mitre.oval:tst:133849"/>
          <criterion comment="perl-Pod-Simple is earlier than 0:3.13-119.el6" test_ref="oval:org.mitre.oval:tst:133728"/>
          <criterion comment="perl-Term-UI is earlier than 0:0.20-119.el6" test_ref="oval:org.mitre.oval:tst:133840"/>
          <criterion comment="perl-Test-Harness is earlier than 0:3.17-119.el6" test_ref="oval:org.mitre.oval:tst:133874"/>
          <criterion comment="perl-Test-Simple is earlier than 0:0.92-119.el6" test_ref="oval:org.mitre.oval:tst:133279"/>
          <criterion comment="perl-Time-HiRes is earlier than 0:1.9721-119.el6" test_ref="oval:org.mitre.oval:tst:133630"/>
          <criterion comment="perl-Time-Piece is earlier than 0:1.15-119.el6" test_ref="oval:org.mitre.oval:tst:133924"/>
          <criterion comment="perl-core is earlier than 0:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:133476"/>
          <criterion comment="perl-devel is earlier than 0:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:133873"/>
          <criterion comment="perl-libs is earlier than 0:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:133402"/>
          <criterion comment="perl-parent is earlier than 0:0.221-119.el6" test_ref="oval:org.mitre.oval:tst:133756"/>
          <criterion comment="perl-suidperl is earlier than 0:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:133639"/>
          <criterion comment="perl-version is earlier than 0:0.77-119.el6" test_ref="oval:org.mitre.oval:tst:133786"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27687" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0500 -- hplip security, bug fix and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>hplip</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0500.html" ref_id="ELSA-2013-0500"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2722" ref_id="CVE-2011-2722"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0200" ref_id="CVE-2013-0200"/>
        <description>[3.12.4-4]

- Applied patch to fix CVE-2013-0200, temporary file vulnerability

  (bug #902163).

- Fixed hpijs-marker-supply patch.



[3.12.4-3]

- Make 'hp-check' check for hpaio set-up correctly (bug #683007).



[3.12.4-2]

- Added more fixes from Fedora (bug #731900).



[3.12.4-1]

- Re-based to 3.12.4 with fixes from Fedora (bug #731900).  No longer

  need no-system-tray, openPPD, addgroup, emit-SIGNAL, fab-root-crash,

  newline, hpaio-segfault, dbus-threads, or cups-web patches.



[3.10.9-4]

- The hpijs sub-package no longer requires cupsddk-drivers (which no

  longer exists as a real package), but cups >= 1.4 (bug #829453).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:02.232-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:39.128-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:38.469-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:54:47.652-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:54:47.652-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="hplip is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:129987"/>
          <criterion comment="hpijs is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:130187"/>
          <criterion comment="hplip-common is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:130210"/>
          <criterion comment="hplip-gui is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:129307"/>
          <criterion comment="hplip-libs is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:129998"/>
          <criterion comment="libsane-hpaio is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:130223"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27686" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1091 -- nss, nspr, and nss-util security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1091.html" ref_id="ELSA-2012-1091"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0441" ref_id="CVE-2012-0441"/>
        <description>nspr
[4.9.1-2]
- Related: rhbz#833762 - Update License to MPLv2.0

[4.9.1-1]
- Resolves: rhbz#833762 - Update to NSPR_4_9_1_RTM

nss
[3.13.5-1.0.1.el6_3 ]
- Added nss-vendor.patch to change vendor
- Use blank image instead of clean.gif in tar ball

[3.13.5-1]
- Resolves: rhbz#834100 - Update to 3.13.5 for mozilla 10.0.6

nss-util
[3.13.5-1]
- Resolves: rhbz#833763 - Update to 3.13.5 for Mozilla 10.0.6</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:23.416-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:38.875-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:38.324-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:21:37.647-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:21:37.647-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.9.1-2.el6_3" test_ref="oval:org.mitre.oval:tst:131577"/>
          <criterion comment="nss is earlier than 0:3.13.5-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131563"/>
          <criterion comment="nss-util is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:131610"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.1-2.el6_3" test_ref="oval:org.mitre.oval:tst:130873"/>
          <criterion comment="nss-devel is earlier than 0:3.13.5-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131450"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.5-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131240"/>
          <criterion comment="nss-sysinit is earlier than 0:3.13.5-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131460"/>
          <criterion comment="nss-tools is earlier than 0:3.13.5-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131241"/>
          <criterion comment="nss-util-devel is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:131543"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27683" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1223 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1223.html" ref_id="ELSA-2012-1223"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0547" ref_id="CVE-2012-0547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1682" ref_id="CVE-2012-1682"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3136" ref_id="CVE-2012-3136"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4681" ref_id="CVE-2012-4681"/>
        <description>[1.7.0.5-2.2.1.0.1.el6_3.3]
- Modify DISTRO_NAME for Oracle

[1.7.0.5-2.2.1.el6.3]
- Removed patch 304 java-1.7.0-openjdk-beans-isPackageAccessible.patch
- Applied upstream patches for same issue:
   patch 1001 sec-webrevs-openjdk7-29_aug_2012-7162473.patch
   patch 1002 sec-webrevs-openjdk7-29_aug_2012-7162476.patch
   patch 1003 sec-webrevs-openjdk7-29_aug_2012-7163201.patch
   patch 1004 sec-webrevs-openjdk7-29_aug_2012-7194567.patch
   patch 1005 sec-webrevs-openjdk7-29_aug_2012-78e01a6ca8d3.patch
- Resolves: rhbz#852299

[1.7.0.5-2.2.1.1.el6]
- Added patch 304 java-1.7.0-openjdk-beans-isPackageAccessible.patch
  to fix vulnerability until it is fixed in upstream sources. 
- Resolves: rhbz#852299</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:39.888-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:38.083-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:37.910-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:09:31.686-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:09:31.686-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130741"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:131079"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130784"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130890"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130490"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27682" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0407 -- libpng security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0407.html" ref_id="ELSA-2012-0407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3045" ref_id="CVE-2011-3045"/>
        <description>[2:1.2.48-1]
- Update to libpng 1.2.48, for minor security issues (CVE-2011-3045)
Resolves: #801663</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:00.610-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:37.845-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:37.764-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:51:12.432-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:51:12.432-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng is earlier than 0:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:131984"/>
            <criterion comment="libpng-devel is earlier than 0:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:132507"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng is earlier than 0:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:132033"/>
            <criterion comment="libpng-devel is earlier than 0:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:132549"/>
            <criterion comment="libpng-static is earlier than 0:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:132552"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27681" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1046 -- php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1046.html" ref_id="ELSA-2012-1046"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2143" ref_id="CVE-2012-2143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4153" ref_id="CVE-2011-4153"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0057" ref_id="CVE-2012-0057"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0789" ref_id="CVE-2012-0789"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1172" ref_id="CVE-2012-1172"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2336" ref_id="CVE-2012-2336"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2950" ref_id="CVE-2010-2950"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2386" ref_id="CVE-2012-2386"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0781" ref_id="CVE-2012-0781"/>
        <description>[5.3.3-14]
- add security fix for CVE-2010-2950

[5.3.3-13]
- fix tests for CVE-2012-2143, CVE-2012-0789

[5.3.3-12]
- add fix for CVE-2012-2336

[5.3.3-11]
- add security fixes for CVE-2012-0781, CVE-2011-4153, CVE-2012-0057,
  CVE-2012-0789, CVE-2012-1172, CVE-2012-2143, CVE-2012-2386

[5.3.3-9]
- correct detection of = in CVE-2012-1823 fix (#818607)

[5.3.3-8]
- add security fix for CVE-2012-1823 (#818607)

[5.3.3-7]
- add security fix for CVE-2012-0830 (#786744)

[5.3.3-6]
- merge Joe's changes:
- improve CVE-2011-1466 fix to cover CAL_GREGORIAN, CAL_JEWISH
- add security fixes for CVE-2011-2483, CVE-2011-0708, CVE-2011-1148,
  CVE-2011-1466, CVE-2011-1468, CVE-2011-1469, CVE-2011-1470,
  CVE-2011-1471, CVE-2011-1938, and CVE-2011-2202 (#740732)

[5.3.3-5]
- remove extra php.ini-prod/devel files caused by %patch -b

[5.3.3-4]
- add security fixes for CVE-2011-4885, CVE-2011-4566 (#769755)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:28.132-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:37.523-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:37.528-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:34:46.968-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:34:46.968-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131579"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131697"/>
          <criterion comment="php-cli is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131668"/>
          <criterion comment="php-common is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131623"/>
          <criterion comment="php-dba is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131750"/>
          <criterion comment="php-devel is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131018"/>
          <criterion comment="php-embedded is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131354"/>
          <criterion comment="php-enchant is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131710"/>
          <criterion comment="php-gd is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131113"/>
          <criterion comment="php-imap is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131763"/>
          <criterion comment="php-intl is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:130888"/>
          <criterion comment="php-ldap is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:130865"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131758"/>
          <criterion comment="php-mysql is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131770"/>
          <criterion comment="php-odbc is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131550"/>
          <criterion comment="php-pdo is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131754"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131666"/>
          <criterion comment="php-process is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131540"/>
          <criterion comment="php-pspell is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131712"/>
          <criterion comment="php-recode is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131741"/>
          <criterion comment="php-snmp is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131664"/>
          <criterion comment="php-soap is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131629"/>
          <criterion comment="php-tidy is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131567"/>
          <criterion comment="php-xml is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131769"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:131690"/>
          <criterion comment="php-zts is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:130907"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27679" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0628 -- 389-ds-base security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0628.html" ref_id="ELSA-2013-0628"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0312" ref_id="CVE-2013-0312"/>
        <description>[1.2.11.15-12]
- Resolves: Bug 910994 - PamConfig schema not updated during upgrade
- Resolves: Bug 910995 - Valgrind reports memleak in modify_update_last_modified_attr
- Resolves: Bug 910996 - DS returns error 20 when replacing values of a multi-valued attribute  (only when replication is enabled)
- Resolves: Bug 911467 - DNA: use event queue for config update only at the start up
- Resolves: Bug 911468 - Error messages encountered when using POSIX winsync
- Resolves: Bug 911469 - dse.ldif is 0 length after server kill or machine kill
- Resolves: Bug 911474 - Invalid chaining config triggers a disk full error and shutdown
- Resolves: Bug 914305 - ns-slapd segfaults while trying to delete a tombstone entry
- Resolves: Bug 913228 - unauthenticated denial of service vulnerability in handling of LDAPv3 control data</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:44.651-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:37.083-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:37.187-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:13:59.162-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:13:59.162-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-12.el6_4" test_ref="oval:org.mitre.oval:tst:129762"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-12.el6_4" test_ref="oval:org.mitre.oval:tst:130087"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-12.el6_4" test_ref="oval:org.mitre.oval:tst:129470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27678" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1580 -- kernel security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1580.html" ref_id="ELSA-2012-1580"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2100" ref_id="CVE-2012-2100"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2375" ref_id="CVE-2012-2375"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4444" ref_id="CVE-2012-4444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4565" ref_id="CVE-2012-4565"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5517" ref_id="CVE-2012-5517"/>
        <description>[2.6.32-279.19.1.el6]
- [drm] i915: dont clobber the pipe param in sanitize_modesetting (Frantisek Hrbata) [876549 857792]
- [drm] i915: Sanitize BIOS debugging bits from PIPECONF (Frantisek Hrbata) [876549 857792]
- [net] fix divide by zero in tcp algorithm illinois (Flavio Leitner) [871920 866514] {CVE-2012-4565}
- [fs] xfs: fix reading of wrapped log data (Dave Chinner) [876499 874322]
- [x86] mm: fix signedness issue in mmap_rnd() (Petr Matousek) [876496 875036]
- [net] WARN if struct ip_options was allocated directly by kmalloc (Jiri Pirko) [877950 872799]
- [fs] block_dev: Fix crash when block device is read and block size is changed at the same time (Frantisek Hrbata) [864826 855906]
- [mm] tracing: Move include of trace/events/kmem.h out of header into slab.c (Jeff Moyer) [864826 855906]
- [mm] slab: Move kmalloc tracepoint out of inline code (Jeff Moyer) [864826 855906]
- [netdrv] bnx2x: organize BDs calculation for stop/resume (Frantisek Hrbata) [874022 819842]
- [netdrv] bnx2x: fix panic when TX ring is full (Michal Schmidt) [874022 819842]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:27.990-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:36.829-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:37.028-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:49:41.878-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:49:41.878-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:130751"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:130634"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:130133"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:130288"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:130822"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:130714"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:130590"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:130547"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:130759"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27675" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-0520 -- dovecot security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0520.html" ref_id="ELSA-2013-0520"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2167" ref_id="CVE-2011-2167"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4318" ref_id="CVE-2011-4318"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2166" ref_id="CVE-2011-2166"/>
        <description>[1:2.0.9-5]
- script-login did not drop privileges correctly (#709095)
- fix directory traversal due to not obeying chroot directive (#709097)
- check proxy destination host against SSL certificate name (#754980)

[1:2.0.9-4]
- dovecot may not set correct premissions for mail folder (#697620)

[1:2.0.9-3]
- fix potential crash when parsing header names that contain NUL characters (#728673)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:58.301-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:36.424-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:36.858-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dovecot is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:129974"/>
          <criterion comment="dovecot-devel is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:129697"/>
          <criterion comment="dovecot-mysql is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:129768"/>
          <criterion comment="dovecot-pgsql is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:129780"/>
          <criterion comment="dovecot-pigeonhole is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:130217"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27674" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0567 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0567.html" ref_id="ELSA-2013-0567"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0871" ref_id="CVE-2013-0871"/>
        <description>[2.6.32-358.0.1]
- [kernel] utrace: ensure arch_ptrace/ptrace_request can never race with SIGKILL (Oleg Nesterov) [912073 912074] {CVE-2013-0871}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:50.121-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:36.269-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:36.759-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:47:06.347-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:47:06.347-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:130176"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:129943"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:130185"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:129356"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:130054"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:130336"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:130117"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:129520"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:130322"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27673" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1261 -- dbus security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1261.html" ref_id="ELSA-2012-1261"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3524" ref_id="CVE-2012-3524"/>
        <description>[1:1.2.24-7.0.1.el6_3 ]
- fix netlink poll: error 4 (Zhenzhong Duan)

[1:1.2.24-7]
- Resolves: #854821

[1:1.2.24-6]
- Apply patches for CVE-2011-2200
- Resolves: #725314</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:28.665-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:36.051-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:36.643-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:51:56.898-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:51:56.898-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dbus is earlier than 0:1.2.24-7.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131066"/>
          <criterion comment="dbus-devel is earlier than 0:1.2.24-7.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130942"/>
          <criterion comment="dbus-doc is earlier than 0:1.2.24-7.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131147"/>
          <criterion comment="dbus-libs is earlier than 0:1.2.24-7.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131112"/>
          <criterion comment="dbus-x11 is earlier than 0:1.2.24-7.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131061"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27672" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2008 -- Unbreakable Enterprise kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2008.html" ref_id="ELSA-2012-2008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1090" ref_id="CVE-2012-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1097" ref_id="CVE-2012-1097"/>
        <description>[2.6.39-100.6.1]

- regset: Return -EFAULT, not -EIO, on host-side memory fault (H. Peter Anvin)

  {CVE-2012-1097}

- regset: Prevent null pointer reference on readonly regsets (H. Peter Anvin)

  {CVE-2012-1097}

- cifs: fix dentry refcount leak when opening a FIFO on lookup (Jeff Layton)

  {CVE-2012-1090}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:23.671-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:35.684-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:36.506-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132392"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132307"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132329"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132010"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132358"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.6.1.el5uek" test_ref="oval:org.mitre.oval:tst:132007"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132514"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132474"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132369"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132245"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:132340"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.6.1.el6uek" test_ref="oval:org.mitre.oval:tst:131798"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27668" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3105 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3105.html" ref_id="ELSA-2014-3105"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3184" ref_id="CVE-2014-3184"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3688" ref_id="CVE-2014-3688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4652" ref_id="CVE-2014-4652"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4656" ref_id="CVE-2014-4656"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6410" ref_id="CVE-2014-6410"/>
        <description>kernel-uek [2.6.32-400.36.12] - HID: fix a couple of off-by-ones (Jiri Kosina)
          [Orabug: 19849320] {CVE-2014-3184} - ALSA: control: Protect user controls against
          concurrent access (Lars-Peter Clausen) [Orabug: 20192545] {CVE-2014-4652} - udf: Avoid
          infinite loop when processing indirect ICBs (Jan Kara) [Orabug: 20192451] {CVE-2014-6410}
          - ALSA: control: Make sure that id->index does not overflow (Lars-Peter Clausen)
          [Orabug: 20192420] {CVE-2014-4656} - ALSA: control: Handle numid overflow (Lars-Peter
          Clausen) [Orabug: 20192379] {CVE-2014-4656} - net: sctp: fix remote memory pressure from
          excessive queueing (Daniel Borkmann) [Orabug: 20192060] {CVE-2014-3688}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-22T10:48:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:12:25.600-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:08.979-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:02.660-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37823 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:40.509-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:29.276-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:137071"/>
            <criterion comment="mlnx_en-2.6.32-400.36.12.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:136721"/>
            <criterion comment="ofa-2.6.32-400.36.12.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136792"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:136144"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:137120"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:136478"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:136589"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:136960"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.12.el5uek" test_ref="oval:org.mitre.oval:tst:137128"/>
            <criterion comment="mlnx_en-2.6.32-400.36.12.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:136412"/>
            <criterion comment="ofa-2.6.32-400.36.12.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136534"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136815"/>
            <criterion comment="mlnx_en-2.6.32-400.36.12.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:136913"/>
            <criterion comment="ofa-2.6.32-400.36.12.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:136877"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136369"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136977"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:137123"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136980"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:137073"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.12.el6uek" test_ref="oval:org.mitre.oval:tst:136377"/>
            <criterion comment="mlnx_en-2.6.32-400.36.12.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:136971"/>
            <criterion comment="ofa-2.6.32-400.36.12.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:137075"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27667" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0830 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0830.html" ref_id="ELSA-2013-0830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2094" ref_id="CVE-2013-2094"/>
        <description>[2.6.32-358.6.2]
- [kernel] perf: fix perf_swevent_enabled array out-of-bound access (Petr Matousek) [962793 962794] {CVE-2013-2094}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:53.765-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:34.786-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:35.905-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:48:37.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:48:37.567-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:129231"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:129487"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:129140"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:129327"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:129341"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:129317"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:128717"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:129544"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:129510"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27664" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0376 -- systemtap security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0376.html" ref_id="ELSA-2012-0376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0875" ref_id="CVE-2012-0875"/>
        <description>[1.6-5.0.1.el6_2]

- remove doc/SystemTap_Beginners_Guide/en-US in tarball

- comment bz683569.patch in specfile

- remove buildtime dependency on package publican-redhat



[1.6-5]

- CVE-2012-0875</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:30.043-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:34.307-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:35.513-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:15:11.208-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:15:11.208-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:132402"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:132611"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:131898"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:131755"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:132302"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:132372"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="systemtap is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132251"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132341"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132598"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132584"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132062"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132437"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-5.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132566"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27663" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0427 -- libtasn1 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtasn1</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0427.html" ref_id="ELSA-2012-0427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1569" ref_id="CVE-2012-1569"/>
        <description>[2.3-3.1]
- fix CVE-2012-1569 - missing length check when decoding DER lengths (#804920)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:06.363-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:34.037-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:35.352-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:18:56.503-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:18:56.503-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libtasn1 is earlier than 0:2.3-3.el6_2.1" test_ref="oval:org.mitre.oval:tst:132227"/>
          <criterion comment="libtasn1-devel is earlier than 0:2.3-3.el6_2.1" test_ref="oval:org.mitre.oval:tst:132466"/>
          <criterion comment="libtasn1-tools is earlier than 0:2.3-3.el6_2.1" test_ref="oval:org.mitre.oval:tst:131917"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27661" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0751 -- java-1.7.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0751.html" ref_id="ELSA-2013-0751"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1557" ref_id="CVE-2013-1557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2424" ref_id="CVE-2013-2424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2436" ref_id="CVE-2013-2436"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2419" ref_id="CVE-2013-2419"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2420" ref_id="CVE-2013-2420"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2421" ref_id="CVE-2013-2421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2426" ref_id="CVE-2013-2426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1558" ref_id="CVE-2013-1558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2430" ref_id="CVE-2013-2430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0401" ref_id="CVE-2013-0401"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1488" ref_id="CVE-2013-1488"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2384" ref_id="CVE-2013-2384"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2422" ref_id="CVE-2013-2422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2431" ref_id="CVE-2013-2431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1569" ref_id="CVE-2013-1569"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2415" ref_id="CVE-2013-2415"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2423" ref_id="CVE-2013-2423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2429" ref_id="CVE-2013-2429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1537" ref_id="CVE-2013-1537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2417" ref_id="CVE-2013-2417"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1518" ref_id="CVE-2013-1518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2383" ref_id="CVE-2013-2383"/>
        <description>[1.7.0.19-2.3.9.1.0.1.el6_4]
- Update DISTRO_NAME in specfile</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:36.933-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:33.642-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:35.031-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:49:52.955-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:49:52.955-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.19-2.3.9.1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129682"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.19-2.3.9.1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129686"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.19-2.3.9.1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128904"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.19-2.3.9.1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129556"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.19-2.3.9.1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129602"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27659" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0095 -- ghostscript security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0095.html" ref_id="ELSA-2012-0095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3743" ref_id="CVE-2009-3743"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2055" ref_id="CVE-2010-2055"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4054" ref_id="CVE-2010-4054"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4820" ref_id="CVE-2010-4820"/>
        <description>[8.70-11:.6]
- Applied upstream fix to last patch (CVE-2010-4054, bug #646086).

[8.70-11:.5]
- Applied patch to prevent null pointer dereference (CVE-2010-4054,
  bug #646086).

[8.70-11:.4]
- Don't ship patch backup files for CVE-2010-2055.

[8.70-11:.3]
- Applied patch to prevent integer underflow in TrueType bytecode
  interpreter (CVE-2009-3743, bug #627902).
- Applied patch to avoid reading initialization files from CWD
  (CVE-2010-2055, bug #599564).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:23.214-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:33.101-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:34.761-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:37:22.025-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:37:22.025-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:132561"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:132781"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:132558"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ghostscript is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:132285"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:132741"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:132522"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:132401"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27658" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1083 -- fuse security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>fuse</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1083.html" ref_id="ELSA-2011-1083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3879" ref_id="CVE-2010-3879"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0541" ref_id="CVE-2011-0541"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0542" ref_id="CVE-2011-0542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0543" ref_id="CVE-2011-0543"/>
        <description>[2.8.3-3]
- Bump the release since the bz was set to the wrong target

[2.8.3-2]
- Fix another umount race (bz# 673250, CVE-2010-3879)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:47.494-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:32.667-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:34.436-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:09:14.417-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:09:14.417-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="fuse is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:133643"/>
          <criterion comment="fuse-devel is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:133583"/>
          <criterion comment="fuse-libs is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:133148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27657" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2504 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2504.html" ref_id="ELSA-2013-2504"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4530" ref_id="CVE-2012-4530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0190" ref_id="CVE-2013-0190"/>
        <description>[2.6.32-300.39.4] - exec: do not leave bprm->interp on stack (Kees Cook)
          [Orabug: 16286741] {CVE-2012-4530} - exec: use -ELOOP for max recursion depth (Kees Cook)
          [Orabug: 16286741] {CVE-2012-4530} [2.6.32-300.39.3] - Xen: Fix stack corruption in
          xen_failsafe_callback for 32bit PVOPS guests. (Frediano Ziglio) [Orabug: 16274192]
          {CVE-2013-0190}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:51.796-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:32.459-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:34.170-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36004 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:40.805-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:28.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130480"/>
            <criterion comment="mlnx_en-2.6.32-300.39.4.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130517"/>
            <criterion comment="ofa-2.6.32-300.39.4.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130440"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130486"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130066"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130444"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:129674"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130108"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.4.el5uek" test_ref="oval:org.mitre.oval:tst:130297"/>
            <criterion comment="mlnx_en-2.6.32-300.39.4.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130454"/>
            <criterion comment="ofa-2.6.32-300.39.4.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130472"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130113"/>
            <criterion comment="mlnx_en-2.6.32-300.39.4.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130483"/>
            <criterion comment="ofa-2.6.32-300.39.4.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130426"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130202"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130461"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130465"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130396"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130451"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.4.el6uek" test_ref="oval:org.mitre.oval:tst:130224"/>
            <criterion comment="mlnx_en-2.6.32-300.39.4.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130026"/>
            <criterion comment="ofa-2.6.32-300.39.4.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130484"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27654" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2507 -- Unbreakable Enterprise kernel security  and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2507.html" ref_id="ELSA-2013-2507"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0228" ref_id="CVE-2013-0228"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0309" ref_id="CVE-2013-0309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0311" ref_id="CVE-2013-0311"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0310" ref_id="CVE-2013-0310"/>
        <description>[2.6.39-400.17.1] 

- This is a fix on dlm_clean_master_list() (Xiaowei.Hu) 

- RDS: fix rds-ping spinlock recursion (jeff.liu) [Orabug: 16223050] 

- vhost: fix length for cross region descriptor (Michael S. Tsirkin) [Orabug: 

16387183] {CVE-2013-0311} 

- kabifix: block/scsi: Allow request and error handling timeouts to be 

specified (Maxim Uvarov) 

- block/scsi: Allow request and error handling timeouts to be specified (Martin 

K. Petersen) [Orabug: 16372401] 

- [SCSI] Shorten the path length of scsi_cmd_to_driver() (Li Zhong) [Orabug: 

16372401] 

- Fix NULL dereferences in scsi_cmd_to_driver (Mark Rustad) [Orabug: 16372401] 

- SCSI: Fix error handling when no ULD is attached (Martin K. Petersen) 

[Orabug: 16372401] 

- Handle disk devices which can not process medium access commands (Martin K. 

Petersen) [Orabug: 16372401] 

- the ac->ac_allow_chain_relink=0 won't disable group relink (Xiaowei.Hu) 

[Orabug: 14842737] 

- pci: hotplug: fix null dereference in pci_set_payload() (Jerry Snitselaar) 

[Orabug: 16345420]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:59.368-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:30.923-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:33.150-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130249"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130255"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130212"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:129353"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130175"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.17.1.el5uek" test_ref="oval:org.mitre.oval:tst:130234"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:130275"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:129989"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:130012"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:130186"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:130304"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.17.1.el6uek" test_ref="oval:org.mitre.oval:tst:129991"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27653" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0188 -- ipa security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ipa</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0188.html" ref_id="ELSA-2013-0188"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5484" ref_id="CVE-2012-5484"/>
        <description>[2.2.0-17.el6_3.1]
- Fix changelog issue. The dist tag was in each entry and changing the
  build release changed history. (#878219)

[2.2.0-17.el6_3]
- Use a secure method to distribute the IPA CA to clients, CVE-2012-5484 (#878219)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:29.517-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:30.790-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:32.969-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:34:50.561-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:34:50.561-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ipa is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:130435"/>
          <criterion comment="ipa-admintools is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:130377"/>
          <criterion comment="ipa-client is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:130001"/>
          <criterion comment="ipa-python is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:129885"/>
          <criterion comment="ipa-server is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:130509"/>
          <criterion comment="ipa-server-selinux is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:130503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27651" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0744 -- python security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0744.html" ref_id="ELSA-2012-0744"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4940" ref_id="CVE-2011-4940"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4944" ref_id="CVE-2011-4944"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0845" ref_id="CVE-2012-0845"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1150" ref_id="CVE-2012-1150"/>
        <description>[2.6.6-29.el6_2.2]
- if hash randomization is enabled, also enable it within pyexpat
Resolves: CVE-2012-0876

[2.6.6-29.el6_2.1]
- distutils.config: create ~/.pypirc securely
Resolves: CVE-2011-4944
- fix endless loop in SimpleXMLRPCServer upon malformed POST request
Resolves: CVE-2012-0845
- send encoding in SimpleHTTPServer.list_directory to protect IE7 against
potential XSS attacks
Resolves: CVE-2011-4940
- oCERT-2011-003: add -R command-line option and PYTHONHASHSEED environment
variable, to provide an opt-in way to protect against denial of service
attacks due to hash collisions within the dict and set types
Resolves: CVE-2012-1150</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:35.081-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:30.410-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:32.659-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:49:51.035-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:49:51.035-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="python is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:131281"/>
          <criterion comment="python-devel is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:131940"/>
          <criterion comment="python-libs is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:131488"/>
          <criterion comment="python-test is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:131661"/>
          <criterion comment="python-tools is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:131674"/>
          <criterion comment="tkinter is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:131918"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27650" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1135 -- libreoffice security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libreoffice</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1135.html" ref_id="ELSA-2012-1135"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2665" ref_id="CVE-2012-2665"/>
        <description>[3.4.5.2-16.1.0.1.el6_3 ]
- Replaced RedHat colors with Oracle colors, and the filename redhat.soc with oracle.soc in specfile
- Build with --with-vendor='Oracle America, Inc.'

[3.4.5.2-16.1]
- Resolves: rhbz#839867 CVE-2012-2665</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:12.804-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:29.743-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:32.171-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:14:54.920-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:14:54.920-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libreoffice is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130999"/>
          <criterion comment="autocorr-af is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131289"/>
          <criterion comment="autocorr-bg is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131077"/>
          <criterion comment="autocorr-cs is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131234"/>
          <criterion comment="autocorr-da is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130744"/>
          <criterion comment="autocorr-de is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131130"/>
          <criterion comment="autocorr-en is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131232"/>
          <criterion comment="autocorr-es is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131371"/>
          <criterion comment="autocorr-eu is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131271"/>
          <criterion comment="autocorr-fa is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130789"/>
          <criterion comment="autocorr-fi is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131205"/>
          <criterion comment="autocorr-fr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131444"/>
          <criterion comment="autocorr-ga is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131351"/>
          <criterion comment="autocorr-hr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130623"/>
          <criterion comment="autocorr-hu is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131120"/>
          <criterion comment="autocorr-it is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131007"/>
          <criterion comment="autocorr-ja is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131331"/>
          <criterion comment="autocorr-ko is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131252"/>
          <criterion comment="autocorr-lb is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130570"/>
          <criterion comment="autocorr-lt is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131361"/>
          <criterion comment="autocorr-mn is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130688"/>
          <criterion comment="autocorr-nl is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131405"/>
          <criterion comment="autocorr-pl is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131415"/>
          <criterion comment="autocorr-pt is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131416"/>
          <criterion comment="autocorr-ru is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130901"/>
          <criterion comment="autocorr-sk is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131245"/>
          <criterion comment="autocorr-sl is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131396"/>
          <criterion comment="autocorr-sr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131377"/>
          <criterion comment="autocorr-sv is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131302"/>
          <criterion comment="autocorr-tr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131206"/>
          <criterion comment="autocorr-vi is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131178"/>
          <criterion comment="autocorr-zh is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130630"/>
          <criterion comment="libreoffice-base is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131167"/>
          <criterion comment="libreoffice-bsh is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130977"/>
          <criterion comment="libreoffice-calc is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130885"/>
          <criterion comment="libreoffice-core is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131048"/>
          <criterion comment="libreoffice-draw is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131454"/>
          <criterion comment="libreoffice-emailmerge is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131267"/>
          <criterion comment="libreoffice-gdb-debug-support is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131239"/>
          <criterion comment="libreoffice-graphicfilter is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131418"/>
          <criterion comment="libreoffice-headless is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130507"/>
          <criterion comment="libreoffice-impress is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131421"/>
          <criterion comment="libreoffice-javafilter is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131262"/>
          <criterion comment="libreoffice-langpack-af is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131288"/>
          <criterion comment="libreoffice-langpack-ar is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131451"/>
          <criterion comment="libreoffice-langpack-as is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131136"/>
          <criterion comment="libreoffice-langpack-bg is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131284"/>
          <criterion comment="libreoffice-langpack-bn is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131414"/>
          <criterion comment="libreoffice-langpack-ca is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131005"/>
          <criterion comment="libreoffice-langpack-cs is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131009"/>
          <criterion comment="libreoffice-langpack-cy is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131333"/>
          <criterion comment="libreoffice-langpack-da is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131247"/>
          <criterion comment="libreoffice-langpack-de is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131031"/>
          <criterion comment="libreoffice-langpack-dz is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131430"/>
          <criterion comment="libreoffice-langpack-el is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131308"/>
          <criterion comment="libreoffice-langpack-en is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130908"/>
          <criterion comment="libreoffice-langpack-es is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131220"/>
          <criterion comment="libreoffice-langpack-et is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131508"/>
          <criterion comment="libreoffice-langpack-eu is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130985"/>
          <criterion comment="libreoffice-langpack-fi is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131315"/>
          <criterion comment="libreoffice-langpack-fr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131461"/>
          <criterion comment="libreoffice-langpack-ga is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131386"/>
          <criterion comment="libreoffice-langpack-gl is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131495"/>
          <criterion comment="libreoffice-langpack-gu is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131352"/>
          <criterion comment="libreoffice-langpack-he is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131224"/>
          <criterion comment="libreoffice-langpack-hi is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131363"/>
          <criterion comment="libreoffice-langpack-hr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131502"/>
          <criterion comment="libreoffice-langpack-hu is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131466"/>
          <criterion comment="libreoffice-langpack-it is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131429"/>
          <criterion comment="libreoffice-langpack-ja is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131280"/>
          <criterion comment="libreoffice-langpack-kn is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131043"/>
          <criterion comment="libreoffice-langpack-ko is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131380"/>
          <criterion comment="libreoffice-langpack-lt is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131485"/>
          <criterion comment="libreoffice-langpack-mai is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130855"/>
          <criterion comment="libreoffice-langpack-ml is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131422"/>
          <criterion comment="libreoffice-langpack-mr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131457"/>
          <criterion comment="libreoffice-langpack-ms is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131486"/>
          <criterion comment="libreoffice-langpack-nb is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130815"/>
          <criterion comment="libreoffice-langpack-nl is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130558"/>
          <criterion comment="libreoffice-langpack-nn is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130859"/>
          <criterion comment="libreoffice-langpack-nr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131364"/>
          <criterion comment="libreoffice-langpack-nso is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131117"/>
          <criterion comment="libreoffice-langpack-or is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131027"/>
          <criterion comment="libreoffice-langpack-pa is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131301"/>
          <criterion comment="libreoffice-langpack-pl is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131175"/>
          <criterion comment="libreoffice-langpack-pt-BR is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131255"/>
          <criterion comment="libreoffice-langpack-pt-PT is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131370"/>
          <criterion comment="libreoffice-langpack-ro is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130933"/>
          <criterion comment="libreoffice-langpack-ru is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131505"/>
          <criterion comment="libreoffice-langpack-sk is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131324"/>
          <criterion comment="libreoffice-langpack-sl is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131447"/>
          <criterion comment="libreoffice-langpack-sr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131172"/>
          <criterion comment="libreoffice-langpack-ss is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131357"/>
          <criterion comment="libreoffice-langpack-st is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130742"/>
          <criterion comment="libreoffice-langpack-sv is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130994"/>
          <criterion comment="libreoffice-langpack-ta is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130519"/>
          <criterion comment="libreoffice-langpack-te is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130892"/>
          <criterion comment="libreoffice-langpack-th is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131455"/>
          <criterion comment="libreoffice-langpack-tn is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130540"/>
          <criterion comment="libreoffice-langpack-tr is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130806"/>
          <criterion comment="libreoffice-langpack-ts is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131321"/>
          <criterion comment="libreoffice-langpack-uk is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131122"/>
          <criterion comment="libreoffice-langpack-ur is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131181"/>
          <criterion comment="libreoffice-langpack-ve is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131462"/>
          <criterion comment="libreoffice-langpack-xh is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131180"/>
          <criterion comment="libreoffice-langpack-zh-Hans is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131353"/>
          <criterion comment="libreoffice-langpack-zh-Hant is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131409"/>
          <criterion comment="libreoffice-langpack-zu is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131515"/>
          <criterion comment="libreoffice-math is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131296"/>
          <criterion comment="libreoffice-ogltrans is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130993"/>
          <criterion comment="libreoffice-opensymbol-fonts is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131013"/>
          <criterion comment="libreoffice-pdfimport is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131012"/>
          <criterion comment="libreoffice-presentation-minimizer is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131471"/>
          <criterion comment="libreoffice-presenter-screen is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131358"/>
          <criterion comment="libreoffice-pyuno is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130927"/>
          <criterion comment="libreoffice-report-builder is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131511"/>
          <criterion comment="libreoffice-rhino is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131516"/>
          <criterion comment="libreoffice-sdk is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131481"/>
          <criterion comment="libreoffice-sdk-doc is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131355"/>
          <criterion comment="libreoffice-testtools is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131237"/>
          <criterion comment="libreoffice-ure is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131047"/>
          <criterion comment="libreoffice-wiki-publisher is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131427"/>
          <criterion comment="libreoffice-writer is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131091"/>
          <criterion comment="libreoffice-xsltfilter is earlier than 0:3.4.5.2-16.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130781"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27649" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0140 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0140.html" ref_id="ELSA-2012-0140"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3026" ref_id="CVE-2011-3026"/>
        <description>[3.1.18-2.0.1.el6_2]
- Replaced thunderbird-redhat-default-prefs.js with
  thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[3.1.18-2]
- added fix for mozbz#727401</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:29.574-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:29.449-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:32.020-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:59:07.253-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:59:07.253-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:3.1.18-2.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132230"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27648" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2035 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2035.html" ref_id="ELSA-2012-2035"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2313" ref_id="CVE-2012-2313"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2390" ref_id="CVE-2012-2390"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3430" ref_id="CVE-2012-3430"/>
        <description>[2.6.32-300.32.3] - dl2k: Clean up rio_ioctl (Stephan Mueller) [Orabug:
          14675306] {CVE-2012-2313} - hugetlb: fix resv_map leak in error path (Christoph Lameter)
          [Orabug: 14676403] {CVE-2012-2390} - rds: set correct msg_namelen (Jay Fenlason) [Orabug:
          14676504] {CVE-2012-3430}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:26.101-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:28.964-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.879-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36021 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:38.357-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:27.868-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130717"/>
            <criterion comment="mlnx_en-2.6.32-300.32.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130427"/>
            <criterion comment="ofa-2.6.32-300.32.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130953"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130978"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130222"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130974"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:131157"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130850"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.32.3.el5uek" test_ref="oval:org.mitre.oval:tst:130561"/>
            <criterion comment="mlnx_en-2.6.32-300.32.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131094"/>
            <criterion comment="ofa-2.6.32-300.32.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131197"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:131119"/>
            <criterion comment="mlnx_en-2.6.32-300.32.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130820"/>
            <criterion comment="ofa-2.6.32-300.32.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130971"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:130643"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:130795"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:131062"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:130814"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:131201"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.32.3.el6uek" test_ref="oval:org.mitre.oval:tst:131169"/>
            <criterion comment="mlnx_en-2.6.32-300.32.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130602"/>
            <criterion comment="ofa-2.6.32-300.32.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130889"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27646" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1359 -- libvirt security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1359.html" ref_id="ELSA-2012-1359"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4423" ref_id="CVE-2012-4423"/>
        <description>[libvirt-0.9.10-21.0.1.el6_3.5]
- Replace docs/et.png in tarball with blank image

[libvirt-0.9.10-21.el6_3.5]
- security: Fix libvirtd crash possibility (CVE-2012-4423)
- Fix augeas test of shared sanlock leases (rhbz#858988)
- qemu augeas: Add spice_tls/spice_tls_x509_cert_dir (rhbz#858988)
- Fix mistakes in augeas lens (rhbz#858988)
- qemu: Fix failure path in disk hotplug (rhbz#859376)
- blockjob: Relabel entire existing chain (rhbz#860720)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:22.143-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:28.562-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.637-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:58:50.674-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:58:50.674-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.9.10-21.0.1.el6_3.5" test_ref="oval:org.mitre.oval:tst:130870"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.0.1.el6_3.5" test_ref="oval:org.mitre.oval:tst:130965"/>
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.0.1.el6_3.5" test_ref="oval:org.mitre.oval:tst:131029"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.0.1.el6_3.5" test_ref="oval:org.mitre.oval:tst:130406"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27645" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0521 -- pam security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pam</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0521.html" ref_id="ELSA-2013-0521"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3148" ref_id="CVE-2011-3148"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3149" ref_id="CVE-2011-3149"/>
        <description>[1.1.1-13]
- fix environment file handling problems - CVE-2011-3148 (#746619) and
  CVE-2011-3148 (#746620)

[1.1.1-12]
- add character sequence test to pam_cracklib
- drop unused difignore option from pam_cracklib (#811243)
- add enforce_for_root option to pam_cracklib (#588893)
- mention limits.d in the limits.conf(5) manpage (#723297)
- add ability to lock out inactive accounts to pam_lastlog
- fix require_selinux option in pam_namespace (#750601)
- add mntopts flag for tmpfs polyinstantiation method
- preserve authtok_type in pam_get_authtok() (#811168)
- fix username mismatch in pam_unix remember feature (#815516)
- relax restriction of root in pam_pwhistory
- relax soft nproc limit for root in 90-nproc.conf

[1.1.1-11]
- additional password checks in pam_cracklib</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:03.321-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:28.227-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.509-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:46:03.831-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:46:03.831-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pam is earlier than 0:1.1.1-13.el6" test_ref="oval:org.mitre.oval:tst:130330"/>
          <criterion comment="pam-devel is earlier than 0:1.1.1-13.el6" test_ref="oval:org.mitre.oval:tst:130024"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27643" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0714 -- stunnel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>stunnel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0714.html" ref_id="ELSA-2013-0714"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1762" ref_id="CVE-2013-1762"/>
        <description>[4.29-3]
Resolves: CVE-2013-1762</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:55.614-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:27.806-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.317-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:16:41.208-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:16:41.208-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="stunnel is earlier than 0:4.29-3.el6_4" test_ref="oval:org.mitre.oval:tst:129647"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27642" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0689 -- bind security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0689.html" ref_id="ELSA-2013-0689"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2266" ref_id="CVE-2013-2266"/>
        <description>[ 32:9.8.2-0.17.rc1.0.2.el6_4.4]
- bump release and build for ULN</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:34.242-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:27.644-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.237-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:35:24.217-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:35:24.217-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.4" test_ref="oval:org.mitre.oval:tst:129664"/>
          <criterion comment="bind-chroot is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.4" test_ref="oval:org.mitre.oval:tst:129632"/>
          <criterion comment="bind-devel is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.4" test_ref="oval:org.mitre.oval:tst:129328"/>
          <criterion comment="bind-libs is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.4" test_ref="oval:org.mitre.oval:tst:129705"/>
          <criterion comment="bind-sdb is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.4" test_ref="oval:org.mitre.oval:tst:129671"/>
          <criterion comment="bind-utils is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.4" test_ref="oval:org.mitre.oval:tst:129486"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27640" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0506 -- rdesktop security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>rdesktop</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0506.html" ref_id="ELSA-2011-0506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1595" ref_id="CVE-2011-1595"/>
        <description>[1.6.0-8.1]
- Prevent remote file access (#676252)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:57.454-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:27.320-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:31.019-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:16:09.026-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:16:09.026-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="rdesktop is earlier than 0:1.6.0-3.el5_6.2" test_ref="oval:org.mitre.oval:tst:133996"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="rdesktop is earlier than 0:1.6.0-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:133812"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27639" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0499 -- xinetd security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0499.html" ref_id="ELSA-2013-0499"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0862" ref_id="CVE-2012-0862"/>
        <description>[2:2.3.14-38]
- CVE-2012-0862 xinetd: enables unintentional services over tcpmux port
- Resolves: #883653

[2:2.3.14-37]
- Fix changelog entry
- Related: #809271

[2:2.3.14-36]
- Fix: Service disabled due to bind failure
- Resolves: #809271</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:34.086-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:27.125-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:30.939-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:07:29.579-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:07:29.579-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="xinetd is earlier than 0:2.3.14-38.el6" test_ref="oval:org.mitre.oval:tst:130022"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27638" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0627 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0627.html" ref_id="ELSA-2013-0627"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0787" ref_id="CVE-2013-0787"/>
        <description>[17.0.3-2.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.3-2]
- Added fix for #848644</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:46.284-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:26.914-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:30.824-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:11:41.073-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:11:41.073-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129156"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129923"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27636" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1455 -- gegl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gegl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1455.html" ref_id="ELSA-2012-1455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4433" ref_id="CVE-2012-4433"/>
        <description>[0.1.2-4]
- avoid buffer overflow in ppm loader (CVE-2012-4433)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:35.658-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:26.697-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:30.716-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:13:06.810-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:13:06.810-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gegl is earlier than 0:0.1.2-4.el6_3" test_ref="oval:org.mitre.oval:tst:130481"/>
          <criterion comment="gegl-devel is earlier than 0:0.1.2-4.el6_3" test_ref="oval:org.mitre.oval:tst:130510"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27634" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0685 -- perl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0685.html" ref_id="ELSA-2013-0685"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5195" ref_id="CVE-2012-5195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1667" ref_id="CVE-2013-1667"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5526" ref_id="CVE-2012-5526"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6329" ref_id="CVE-2012-6329"/>
        <description>[4:5.10.1-130]
- Resolves: #915692 - CVE-2012-5526 (newline injection due to improper CRLF
  escaping in Set-Cookie and P3P headers)
- Resolves: #915692 - CVE-2012-6329 (possible arbitrary code execution via
  Locale::Maketext)
- Resolves: #915692 - CVE-2013-1667 (DoS in rehashing code)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:58.974-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:25.701-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:29.918-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:18:35.217-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:18:35.217-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="perl is earlier than 0:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:129844"/>
            <criterion comment="perl-suidperl is earlier than 0:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:129536"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="perl is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129757"/>
            <criterion comment="perl-Archive-Extract is earlier than 0:0.38-130.el6_4" test_ref="oval:org.mitre.oval:tst:129433"/>
            <criterion comment="perl-Archive-Tar is earlier than 0:1.58-130.el6_4" test_ref="oval:org.mitre.oval:tst:129687"/>
            <criterion comment="perl-CGI is earlier than 0:3.51-130.el6_4" test_ref="oval:org.mitre.oval:tst:129745"/>
            <criterion comment="perl-CPAN is earlier than 0:1.9402-130.el6_4" test_ref="oval:org.mitre.oval:tst:129177"/>
            <criterion comment="perl-CPANPLUS is earlier than 0:0.88-130.el6_4" test_ref="oval:org.mitre.oval:tst:129007"/>
            <criterion comment="perl-Compress-Raw-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129862"/>
            <criterion comment="perl-Compress-Raw-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129628"/>
            <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129690"/>
            <criterion comment="perl-Digest-SHA is earlier than 0:5.47-130.el6_4" test_ref="oval:org.mitre.oval:tst:129832"/>
            <criterion comment="perl-ExtUtils-CBuilder is earlier than 0:0.27-130.el6_4" test_ref="oval:org.mitre.oval:tst:129711"/>
            <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-130.el6_4" test_ref="oval:org.mitre.oval:tst:129063"/>
            <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-130.el6_4" test_ref="oval:org.mitre.oval:tst:129774"/>
            <criterion comment="perl-ExtUtils-ParseXS is earlier than 0:2.2003.0-130.el6_4" test_ref="oval:org.mitre.oval:tst:128898"/>
            <criterion comment="perl-File-Fetch is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:129751"/>
            <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129827"/>
            <criterion comment="perl-IO-Compress-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129565"/>
            <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:129583"/>
            <criterion comment="perl-IO-Zlib is earlier than 0:1.09-130.el6_4" test_ref="oval:org.mitre.oval:tst:129836"/>
            <criterion comment="perl-IPC-Cmd is earlier than 0:0.56-130.el6_4" test_ref="oval:org.mitre.oval:tst:129723"/>
            <criterion comment="perl-Locale-Maketext-Simple is earlier than 0:0.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:129644"/>
            <criterion comment="perl-Log-Message is earlier than 0:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:129840"/>
            <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:129892"/>
            <criterion comment="perl-Module-Build is earlier than 0:0.3500-130.el6_4" test_ref="oval:org.mitre.oval:tst:129782"/>
            <criterion comment="perl-Module-CoreList is earlier than 0:2.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:129527"/>
            <criterion comment="perl-Module-Load is earlier than 0:0.16-130.el6_4" test_ref="oval:org.mitre.oval:tst:129080"/>
            <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-130.el6_4" test_ref="oval:org.mitre.oval:tst:129335"/>
            <criterion comment="perl-Module-Loaded is earlier than 0:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:129880"/>
            <criterion comment="perl-Module-Pluggable is earlier than 0:3.90-130.el6_4" test_ref="oval:org.mitre.oval:tst:129413"/>
            <criterion comment="perl-Object-Accessor is earlier than 0:0.34-130.el6_4" test_ref="oval:org.mitre.oval:tst:129558"/>
            <criterion comment="perl-Package-Constants is earlier than 0:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:129868"/>
            <criterion comment="perl-Params-Check is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:129215"/>
            <criterion comment="perl-Parse-CPAN-Meta is earlier than 0:1.40-130.el6_4" test_ref="oval:org.mitre.oval:tst:129475"/>
            <criterion comment="perl-Pod-Escapes is earlier than 0:1.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:129587"/>
            <criterion comment="perl-Pod-Simple is earlier than 0:3.13-130.el6_4" test_ref="oval:org.mitre.oval:tst:129817"/>
            <criterion comment="perl-Term-UI is earlier than 0:0.20-130.el6_4" test_ref="oval:org.mitre.oval:tst:128944"/>
            <criterion comment="perl-Test-Harness is earlier than 0:3.17-130.el6_4" test_ref="oval:org.mitre.oval:tst:129808"/>
            <criterion comment="perl-Test-Simple is earlier than 0:0.92-130.el6_4" test_ref="oval:org.mitre.oval:tst:129890"/>
            <criterion comment="perl-Time-HiRes is earlier than 0:1.9721-130.el6_4" test_ref="oval:org.mitre.oval:tst:129416"/>
            <criterion comment="perl-Time-Piece is earlier than 0:1.15-130.el6_4" test_ref="oval:org.mitre.oval:tst:129831"/>
            <criterion comment="perl-core is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129821"/>
            <criterion comment="perl-devel is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129392"/>
            <criterion comment="perl-libs is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129741"/>
            <criterion comment="perl-parent is earlier than 0:0.221-130.el6_4" test_ref="oval:org.mitre.oval:tst:129916"/>
            <criterion comment="perl-suidperl is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:129732"/>
            <criterion comment="perl-version is earlier than 0:0.77-130.el6_4" test_ref="oval:org.mitre.oval:tst:129798"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27633" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1268 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1268.html" ref_id="ELSA-2012-1268"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4244" ref_id="CVE-2012-4244"/>
        <description>[32:9.8.2-0.10.rc1.3]
- fix  CVE-2012-4244</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:13.441-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:25.509-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:29.740-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:06:19.841-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:06:19.841-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 0:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:131139"/>
          <criterion comment="bind-chroot is earlier than 0:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:131177"/>
          <criterion comment="bind-devel is earlier than 0:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130876"/>
          <criterion comment="bind-libs is earlier than 0:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130881"/>
          <criterion comment="bind-sdb is earlier than 0:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:130862"/>
          <criterion comment="bind-utils is earlier than 0:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:131038"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27631" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0245 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0245.html" ref_id="ELSA-2013-0245"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0424" ref_id="CVE-2013-0424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0425" ref_id="CVE-2013-0425"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0426" ref_id="CVE-2013-0426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0427" ref_id="CVE-2013-0427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0428" ref_id="CVE-2013-0428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0429" ref_id="CVE-2013-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0432" ref_id="CVE-2013-0432"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0433" ref_id="CVE-2013-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0434" ref_id="CVE-2013-0434"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0435" ref_id="CVE-2013-0435"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0440" ref_id="CVE-2013-0440"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0441" ref_id="CVE-2013-0441"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0442" ref_id="CVE-2013-0442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0443" ref_id="CVE-2013-0443"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0445" ref_id="CVE-2013-0445"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0450" ref_id="CVE-2013-0450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1475" ref_id="CVE-2013-1475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1476" ref_id="CVE-2013-1476"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1478" ref_id="CVE-2013-1478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1480" ref_id="CVE-2013-1480"/>
        <description>[1:1.6.0.0-1.54.1.11.6]
- removed patch8 revertTwoWrongSecurityPatches2013-02-06.patch
- added patch8:   7201064.patch to be reverted
- added patch9:   8005615.patch to fix the 6664509.patch
- Resolves: rhbz#906707

[1:1.6.0.0-1.53.1.11.6]
- added patch8 revertTwoWrongSecurityPatches2013-02-06.patch
  to remove   6664509 and 7201064 from 1.11.6 tarball
- Resolves: rhbz#906707

[1:1.6.0.0-1.51.1.11.6]
- Updated to icedtea6 1.11.6
- Rewritten java-1.6.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#906707</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:44.218-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:24.726-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:29.337-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:18:51.813-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:18:51.813-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:130265"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:130246"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:130360"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:130375"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:130429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27629" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2048 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2048.html" ref_id="ELSA-2012-2048"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2100" ref_id="CVE-2012-2100"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4444" ref_id="CVE-2012-4444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4565" ref_id="CVE-2012-4565"/>
        <description>[2.6.32-300.39.2] - ext4: fix undefined behavior in ext4_fill_flex_info() (Xi
          Wang) [orabug 16020245] {CVE-2012-2100} - Divide by zero in TCP congestion control
          Algorithm (Jesper Dangaard Brouer) [orabug 16020447] {CVE-2012-4565} - ipv6: discard
          overlapping fragment (Luis Henriques) [orabug 16021354] {CVE-2012-4444}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:26.780-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:24.139-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:28.858-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36084 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:37.465-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:26.985-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130296"/>
            <criterion comment="mlnx_en-2.6.32-300.39.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130390"/>
            <criterion comment="ofa-2.6.32-300.39.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130753"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130767"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130752"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:129823"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130607"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130595"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.2.el5uek" test_ref="oval:org.mitre.oval:tst:130804"/>
            <criterion comment="mlnx_en-2.6.32-300.39.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130787"/>
            <criterion comment="ofa-2.6.32-300.39.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130819"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130761"/>
            <criterion comment="mlnx_en-2.6.32-300.39.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130541"/>
            <criterion comment="ofa-2.6.32-300.39.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130724"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130704"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130803"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130463"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130442"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130698"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.2.el6uek" test_ref="oval:org.mitre.oval:tst:130580"/>
            <criterion comment="mlnx_en-2.6.32-300.39.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129846"/>
            <criterion comment="ofa-2.6.32-300.39.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130040"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27627" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1549 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1549.html" ref_id="ELSA-2012-1549"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5688" ref_id="CVE-2012-5688"/>
        <description>[32:9.8.2-0.10.rc1.6]
- fix CVE-2012-5688</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:44.505-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:23.767-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:28.543-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:33:47.947-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:33:47.947-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 0:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:130750"/>
          <criterion comment="bind-chroot is earlier than 0:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:130757"/>
          <criterion comment="bind-devel is earlier than 0:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:130494"/>
          <criterion comment="bind-libs is earlier than 0:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:130648"/>
          <criterion comment="bind-sdb is earlier than 0:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:130776"/>
          <criterion comment="bind-utils is earlier than 0:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:130592"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27626" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1326 -- freeradius security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>freeradius</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1326.html" ref_id="ELSA-2012-1326"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3547" ref_id="CVE-2012-3547"/>
        <description>[2.1.12-4]
- resolves: bug#855316
  CVE-2012-3547 freeradius: Stack-based buffer overflow by processing
  certain expiration date fields of a certificate during x509 certificate
  validation</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:23.733-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:23.355-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:28.403-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:52:15.866-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:52:15.866-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="freeradius is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:130918"/>
          <criterion comment="freeradius-krb5 is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:130658"/>
          <criterion comment="freeradius-ldap is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:131182"/>
          <criterion comment="freeradius-mysql is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:130875"/>
          <criterion comment="freeradius-perl is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:131144"/>
          <criterion comment="freeradius-postgresql is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:130909"/>
          <criterion comment="freeradius-python is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:131088"/>
          <criterion comment="freeradius-unixODBC is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:131057"/>
          <criterion comment="freeradius-utils is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:131089"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27625" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0393 -- glibc security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0393.html" ref_id="ELSA-2012-0393"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0864" ref_id="CVE-2012-0864"/>
        <description>[2.12-1.47.el6_2.9]
- Always use another area after a failed allocation in the
    main arena (#795328)
  - Remove sse3 memcpy (#695812) changes (#799259)

[2.12-1.47.el6_2.8]
- Avoid nargs integer overflow which could be used to bypass FORTIFY_SOURCE (#794815)

[2.12-1.47.el6_2.7]
- Fix locking on malloc family retry paths (#795328)

[2.12-1.47.el6_2.6]
- Fix cycle detection in dynamic loader (#783999)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:04.592-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:23.118-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:28.305-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:57:46.207-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:57:46.207-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:132491"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:132169"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:131628"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:132626"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:132518"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:132582"/>
          <criterion comment="nscd is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:132275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27624" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1459 -- nspluginwrapper security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspluginwrapper</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1459.html" ref_id="ELSA-2012-1459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2486" ref_id="CVE-2011-2486"/>
        <description>[1.4.4-1]
- Rebase the package to latest upstream
- Added Adobe reader fix (#645599)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:24.491-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:22.897-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:28.227-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:20:01.560-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:20:01.560-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="nspluginwrapper is earlier than 0:1.4.4-1.el6_3" test_ref="oval:org.mitre.oval:tst:130599"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27622" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2520 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2520.html" ref_id="ELSA-2013-2520"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6546" ref_id="CVE-2012-6546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1796" ref_id="CVE-2013-1796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6537" ref_id="CVE-2012-6537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0309" ref_id="CVE-2013-0309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0310" ref_id="CVE-2013-0310"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1792" ref_id="CVE-2013-1792"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1798" ref_id="CVE-2013-1798"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0871" ref_id="CVE-2013-0871"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1774" ref_id="CVE-2013-1774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6547" ref_id="CVE-2012-6547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5517" ref_id="CVE-2012-5517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0349" ref_id="CVE-2013-0349"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1827" ref_id="CVE-2013-1827"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4508" ref_id="CVE-2012-4508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1826" ref_id="CVE-2013-1826"/>
        <description>[2.6.32-400.26.2] - mm/hotplug: correctly add new zone to all other nodes' zone
          lists (Jiang Liu) [Orabug: 16603569] {CVE-2012-5517} - ptrace: ptrace_resume() shouldn't
          wake up !TASK_TRACED thread (Oleg Nesterov) [Orabug: 16405868] {CVE-2013-0871} - ptrace:
          ensure arch_ptrace/ptrace_request can never race with SIGKILL (Oleg Nesterov) [Orabug:
          16405868] {CVE-2013-0871} - ptrace: introduce signal_wake_up_state() and
          ptrace_signal_wake_up() (Oleg Nesterov) [Orabug: 16405868] {CVE-2013-0871} - Bluetooth:
          Fix incorrect strncpy() in hidp_setup_hid() (Anderson Lizardo) [Orabug: 16711062]
          {CVE-2013-0349} - dccp: check ccid before dereferencing (Mathias Krause) [Orabug:
          16711040] {CVE-2013-1827} - USB: io_ti: Fix NULL dereference in chase_port() (Wolfgang
          Frisch) [Orabug: 16425435] {CVE-2013-1774} - keys: fix race with concurrent
          install_user_keyrings() (David Howells) [Orabug: 16493369] {CVE-2013-1792} - KVM: Fix
          bounds checking in ioapic indirect register reads (CVE-2013-1798) (Andy Honig) [Orabug:
          16710937] {CVE-2013-1798} - KVM: x86: fix for buffer overflow in handling of
          MSR_KVM_SYSTEM_TIME (CVE-2013-1796) (Jerry Snitselaar) [Orabug: 16710794] {CVE-2013-1796}
          - net/tun: fix ioctl() based info leaks (Mathias Krause) [Orabug: 16675501]
          {CVE-2012-6547} - atm: fix info leak via getsockname() (Mathias Krause) [Orabug: 16675501]
          {CVE-2012-6546} - atm: fix info leak in getsockopt(SO_ATMPVC) (Mathias Krause) [Orabug:
          16675501] {CVE-2012-6546} - xfrm_user: fix info leak in copy_to_user_tmpl() (Mathias
          Krause) [Orabug: 16675501] {CVE-2012-6537} - xfrm_user: fix info leak in
          copy_to_user_policy() (Mathias Krause) [Orabug: 16675501] {CVE-2012-6537} - xfrm_user: fix
          info leak in copy_to_user_state() (Mathias Krause) [Orabug: 16675501] {CVE-2013-6537} -
          xfrm_user: return error pointer instead of NULL #2 (Mathias Krause) [Orabug: 16675501]
          {CVE-2013-1826} - xfrm_user: return error pointer instead of NULL (Mathias Krause)
          [Orabug: 16675501] {CVE-2013-1826}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:37.975-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:22.353-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:27.808-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:129531 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:41.097-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:25.897-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129044"/>
            <criterion comment="mlnx_en-2.6.32-400.26.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129375"/>
            <criterion comment="ofa-2.6.32-400.26.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129677"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129704"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129579"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129166"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129236"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129675"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.26.2.el5uek" test_ref="oval:org.mitre.oval:tst:129449"/>
            <criterion comment="mlnx_en-2.6.32-400.26.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129441"/>
            <criterion comment="ofa-2.6.32-400.26.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129225"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129537"/>
            <criterion comment="mlnx_en-2.6.32-400.26.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129531"/>
            <criterion comment="ofa-2.6.32-400.26.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129461"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129292"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129605"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129684"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129658"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129479"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.26.2.el6uek" test_ref="oval:org.mitre.oval:tst:129663"/>
            <criterion comment="mlnx_en-2.6.32-400.26.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129708"/>
            <criterion comment="ofa-2.6.32-400.26.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129695"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27621" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1208 -- glibc security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1208.html" ref_id="ELSA-2012-1208"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3480" ref_id="CVE-2012-3480"/>
        <description>[2.12-1.80.el6_3.5]
- Fix integer overflow leading to buffer overflow in strto*
  and related out of bounds array index (#847931)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:13.756-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:22.081-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:27.648-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:07:24.531-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:07:24.531-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:131171"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:131192"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:131323"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:130947"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:131306"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:130672"/>
          <criterion comment="nscd is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:130501"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27618" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0646 -- pidgin security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0646.html" ref_id="ELSA-2013-0646"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0272" ref_id="CVE-2013-0272"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0273" ref_id="CVE-2013-0273"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0274" ref_id="CVE-2013-0274"/>
        <description>[2.7.9-10.el6_4.1]
- Fix spec file for disttag

[2.7.9-10.el6]
- Add patch for CVE-2013-0274 (RH bug #910653).

[2.7.9-9.el6]
- Add patch for CVE-2013-0273 (RH bug #910653).

[2.7.9-8.el6]
- Add patch for CVE-2013-0272 (RH bug #910653).

[2.7.9-7.el6]
- Add patch for CVE-2011-2485 (RH bug #837562).

[2.7.9-6.el6]
- Add patch for CVE-2012-1178 (RH bug #837560).
- Add patch for CVE-2012-2318 (RH bug #837560).
- Add patch for CVE-2012-3374 (RH bug #837560).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:39.707-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:21.325-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:27.201-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:31:37.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:31:37.713-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pidgin is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129886"/>
            <criterion comment="finch is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129905"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129752"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129922"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129324"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129692"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129625"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:129438"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:128962"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pidgin is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129810"/>
            <criterion comment="finch is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129915"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129920"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129826"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129865"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129938"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129800"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129365"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129655"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129863"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27617" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0774 -- libguestfs security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libguestfs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0774.html" ref_id="ELSA-2012-0774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2690" ref_id="CVE-2012-2690"/>
        <description>[1:1.16.19-1]
- Rebase to libguestfs 1.16.19
  resolves: rhbz#719879
- Rebuild against augeas 0.9.0-3.el6
  related: rhbz#808662
- Fix: Don't abort inspection if mdadm.conf ARRAY doesn't have a uuid.
- Switch back to git for patch management.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:36.983-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:21.104-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:27.024-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:43:52.703-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:43:52.703-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="libguestfs is earlier than 0:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:131607"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27614" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0862 -- Oracle Linux 6 kernel security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0862.html" ref_id="ELSA-2012-0862"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1083" ref_id="CVE-2011-1083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4131" ref_id="CVE-2011-4131"/>
        <description>[2.6.32-279.el6]
- [netdrv] mlx4: ignore old module parameters (Jay Fenlason) [830553]

[2.6.32-278.el6]
- [kernel] sysctl: silence warning about missing strategy for file-max at boot time (Jeff Layton) [803431]
- [net] sunrpc: make new tcp_max_slot_table_entries sysctl use CTL_UNNUMBERED (Jeff Layton) [803431]
- [drm] i915: set AUD_CONFIG N_value_index for DisplayPort (Dave Airlie) [747890]
- [scsi] scsi_lib: fix scsi_io_completions SG_IO error propagation (Mike Snitzer) [827163]
- [fs] nfs: Fix corrupt read data after short READ from server (Sachin Prabhu) [817738]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:33.454-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:19.277-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:25.724-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:20:54.919-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:20:54.919-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:131498"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:131676"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:131314"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:131648"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:131717"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:131795"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:131634"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:130829"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:130842"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27613" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0981 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0981.html" ref_id="ELSA-2013-0981"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1682" ref_id="CVE-2013-1682"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1684" ref_id="CVE-2013-1684"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1685" ref_id="CVE-2013-1685"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1686" ref_id="CVE-2013-1686"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1687" ref_id="CVE-2013-1687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1690" ref_id="CVE-2013-1690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1692" ref_id="CVE-2013-1692"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1693" ref_id="CVE-2013-1693"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1694" ref_id="CVE-2013-1694"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1697" ref_id="CVE-2013-1697"/>
        <description>firefox
[17.0.7-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.7-1]
- Update to 17.0.7 ESR

xulrunner
[17.0.7-1.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.7-1]
- Update to 17.0.7 ESR

[17.0.6-5]
- Added workaround for rhbz#973721 - fixing problem with installation
  of  some addons

[17.0.6-4]
- Added a workaround for rhbz#961687 - Prelink throws message
  'Cannot safely convert .rel.dyn' section from REL to RELA'

[17.0.6-3]
- Added patch for aliasing issues (mozbz#821502)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:18.416-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:19.093-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:25.541-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:10:10.395-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:10:10.395-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.7-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129431"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129405"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128895"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.7-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128971"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129186"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129167"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27611" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0883 -- gnutls security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0883.html" ref_id="ELSA-2013-0883"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2116" ref_id="CVE-2013-2116"/>
        <description>[2.8.5-10.2]
- fix CVE-2013-2116 - fix DoS regression in CVE-2013-1619
  upstream patch (#966754)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:24.608-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:18.849-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:25.339-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:19:57.367-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:19:57.367-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:129491"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:129350"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:129483"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129332"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129242"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129319"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129463"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27609" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0699 -- openssl security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0699.html" ref_id="ELSA-2012-0699"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2333" ref_id="CVE-2012-2333"/>
        <description>[1.0.0-20.5]
- fix for CVE-2012-2333 - improper checking for record length in DTLS (#820686)
- properly initialize tkeylen in the CVE-2012-0884 fix</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:09.219-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:18.636-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:25.149-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:35:31.480-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:35:31.480-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:132098"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:131997"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:131901"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:132009"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:131652"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:131269"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:132115"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27608" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0772 -- mysql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0772.html" ref_id="ELSA-2013-0772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5614" ref_id="CVE-2012-5614"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1521" ref_id="CVE-2013-1521"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1531" ref_id="CVE-2013-1531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1555" ref_id="CVE-2013-1555"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2391" ref_id="CVE-2013-2391"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2392" ref_id="CVE-2013-2392"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1532" ref_id="CVE-2013-1532"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1544" ref_id="CVE-2013-1544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1548" ref_id="CVE-2013-1548"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1552" ref_id="CVE-2013-1552"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2375" ref_id="CVE-2013-2375"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1506" ref_id="CVE-2013-1506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2378" ref_id="CVE-2013-2378"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2389" ref_id="CVE-2013-2389"/>
        <description>[5.1.69-1]
- Update to 5.1.69, for assorted upstream bugfixes including
  CVEs announced in April 2013
Resolves: #953084</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:00.662-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:17.073-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:24.143-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:58:38.259-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:58:38.259-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:129138"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:129645"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:129588"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:129404"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:129654"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:129621"/>
          <criterion comment="mysql-server is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:129548"/>
          <criterion comment="mysql-test is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:129532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27607" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0145 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0145.html" ref_id="ELSA-2013-0145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0744" ref_id="CVE-2013-0744"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0746" ref_id="CVE-2013-0746"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0748" ref_id="CVE-2013-0748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0750" ref_id="CVE-2013-0750"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0753" ref_id="CVE-2013-0753"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0754" ref_id="CVE-2013-0754"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0758" ref_id="CVE-2013-0758"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0759" ref_id="CVE-2013-0759"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0762" ref_id="CVE-2013-0762"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0766" ref_id="CVE-2013-0766"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0767" ref_id="CVE-2013-0767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0769" ref_id="CVE-2013-0769"/>
        <description>[10.0.12-3.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[10.0.12-3]
- Update to 10.0.12 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:25.452-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:16.914-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:24.017-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:59:41.471-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:59:41.471-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129792"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130562"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27605" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0587 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0587.html" ref_id="ELSA-2013-0587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0166" ref_id="CVE-2013-0166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4929" ref_id="CVE-2012-4929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0169" ref_id="CVE-2013-0169"/>
        <description>[1.0.0-27.2]
- fix for CVE-2013-0169 - SSL/TLS CBC timing attack (#907589)
- fix for CVE-2013-0166 - DoS in OCSP signatures checking (#908052)
- enable compression only if explicitly asked for or OPENSSL_DEFAULT_ZLIB
  environment variable is set (fixes CVE-2012-4929 #857051)
- use __secure_getenv() everywhere instead of getenv() (#839735)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:50.662-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:16.246-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:23.578-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:32:12.519-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:32:12.519-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:130221"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:130232"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:129978"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:130167"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:129799"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:130172"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:129772"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27604" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0509 -- wireshark security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0509.html" ref_id="ELSA-2012-0509"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1143" ref_id="CVE-2011-1143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1590" ref_id="CVE-2011-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1957" ref_id="CVE-2011-1957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1958" ref_id="CVE-2011-1958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1959" ref_id="CVE-2011-1959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2174" ref_id="CVE-2011-2174"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2175" ref_id="CVE-2011-2175"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2597" ref_id="CVE-2011-2597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2698" ref_id="CVE-2011-2698"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4102" ref_id="CVE-2011-4102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0041" ref_id="CVE-2012-0041"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0042" ref_id="CVE-2012-0042"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0066" ref_id="CVE-2012-0066"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0067" ref_id="CVE-2012-0067"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1595" ref_id="CVE-2012-1595"/>
        <description>[1.2.15-2.0.1.el6_2.1]
- Add oracle-ocfs2-network.patch to allow disassembly of OCFS2 interconnect

[1.2.15-2.1]
- security patches
- Resolves: CVE-2011-1143
            CVE-2011-1590
            CVE-2011-1957
            CVE-2011-1959
            CVE-2011-2174
            CVE-2011-2175 CVE-2011-1958
            CVE-2011-2597 CVE-2011-2698
            CVE-2011-4102
            CVE-2012-0041 CVE-2012-0066 CVE-2012-0067
            CVE-2012-0042
            CVE-2012-1595</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:29.960-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:15.436-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:22.980-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:02:28.810-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:02:28.810-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="wireshark is earlier than 0:1.2.15-2.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132447"/>
          <criterion comment="wireshark-devel is earlier than 0:1.2.15-2.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132288"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.2.15-2.0.1.el6_2.1" test_ref="oval:org.mitre.oval:tst:132517"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27603" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0942 -- krb5 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0942.html" ref_id="ELSA-2013-0942"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2443" ref_id="CVE-2002-2443"/>
        <description>[1.10.3-10.3]
- pull up fix for UDP ping-pong flaw in kpasswd service (CVE-2002-2443,</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:34.864-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:15.174-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:22.773-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:28:17.500-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:28:17.500-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="krb5 is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:128767"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:128623"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:129006"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:129313"/>
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:128925"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:129155"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129346"/>
            <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129131"/>
            <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129181"/>
            <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129323"/>
            <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:128864"/>
            <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129152"/>
            <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:129390"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27602" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2511 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2511.html" ref_id="ELSA-2013-2511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0268" ref_id="CVE-2013-0268"/>
        <description>[2.6.39-400.17.2]
- x86/msr: Add capabilities check (Alan Cox) [Orabug: 16405007] {CVE-2013-0268}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:55.420-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:14.983-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:22.633-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129783"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129743"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130034"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:130029"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129508"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.17.2.el5uek" test_ref="oval:org.mitre.oval:tst:129737"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129878"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:130037"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129088"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129263"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129648"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.17.2.el6uek" test_ref="oval:org.mitre.oval:tst:129815"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27599" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1289 -- librsvg2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>librsvg2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1289.html" ref_id="ELSA-2011-1289"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3146" ref_id="CVE-2011-3146"/>
        <description>[2.26.0-5.el6_1.1]
- Store node type separately in RsvgNode (CVE-2011-3146)
  Resolves: #735266</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:17.412-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:14.772-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:22.462-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:03:04.705-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:03:04.705-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="librsvg2 is earlier than 0:2.26.0-5.el6_1.1" test_ref="oval:org.mitre.oval:tst:133448"/>
          <criterion comment="librsvg2-devel is earlier than 0:2.26.0-5.el6_1.1" test_ref="oval:org.mitre.oval:tst:132564"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27598" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0999 -- libvpx security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvpx</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0999.html" ref_id="ELSA-2010-0999"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4203" ref_id="CVE-2010-4203"/>
        <description>[0.9.0-8]
- Fix CVE-2010-4203
Resolves: rhbz#652440

[0.9.0-7]
- Import 0.9.0-6 package from Fedora
- Add patch porting yasm syntax to gas
Related: rhbz#603113</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:43.421-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:14.449-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:22.335-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:21:44.757-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:21:44.757-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvpx is earlier than 0:0.9.0-8.el6_0" test_ref="oval:org.mitre.oval:tst:134295"/>
          <criterion comment="libvpx-devel is earlier than 0:0.9.0-8.el6_0" test_ref="oval:org.mitre.oval:tst:134241"/>
          <criterion comment="libvpx-utils is earlier than 0:0.9.0-8.el6_0" test_ref="oval:org.mitre.oval:tst:134298"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27597" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0080 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0080.html" ref_id="ELSA-2012-0080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3659" ref_id="CVE-2011-3659"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3670" ref_id="CVE-2011-3670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0442" ref_id="CVE-2012-0442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0449" ref_id="CVE-2012-0449"/>
        <description>[3.1.18-1.0.1.el6_2]
- Replaced thunderbird-redhat-default-prefs.js with
  thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[3.1.18-1]
- Update to 3.1.18</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:18.273-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:13.968-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:22.067-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:28:45.336-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:28:45.336-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:3.1.18-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27596" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2038 -- Unbreakable Enterprise kernel security and bug fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2038.html" ref_id="ELSA-2012-2038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <description>[2.6.32-300.37.1.] - sfc: Replace some literal constants with
          EFX_PAGE_SIZE/EFX_BUF_SIZE (Ben Hutchings) [Orabug: 14769994] - CVE-2012-3412 sfc: Fix
          maximum number of TSO segments and minimum TX queue size (Ben Hutchings) [Orabug:
          14769994] {CVE-2012-3412}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:45.970-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:13.757-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:21.796-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27596 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:35.604-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:25.391-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:130966"/>
            <criterion comment="mlnx_en-2.6.32-300.37.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130701"/>
            <criterion comment="ofa-2.6.32-300.37.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130805"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:131059"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:130989"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:131052"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:130639"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:131021"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.37.1.el5uek" test_ref="oval:org.mitre.oval:tst:130170"/>
            <criterion comment="mlnx_en-2.6.32-300.37.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130798"/>
            <criterion comment="ofa-2.6.32-300.37.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130738"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:130839"/>
            <criterion comment="mlnx_en-2.6.32-300.37.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131072"/>
            <criterion comment="ofa-2.6.32-300.37.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130884"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:131118"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:130682"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:131041"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:131070"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:131150"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.37.1.el6uek" test_ref="oval:org.mitre.oval:tst:130903"/>
            <criterion comment="mlnx_en-2.6.32-300.37.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130689"/>
            <criterion comment="ofa-2.6.32-300.37.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130914"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27593" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0602 -- java-1.7.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0602.html" ref_id="ELSA-2013-0602"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0809" ref_id="CVE-2013-0809"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1493" ref_id="CVE-2013-1493"/>
        <description>[1.7.0.9-2.3.8.0.0.1.el6_4]
- Update DISTRO_NAME in specfile

[1.7.0.9-2.3.8.0el6]
- Revert to rhel 6.3 version of spec file
- Revert to icedtea7 2.3.8 forest
- Resolves: rhbz#917183

[1.7.0.11-2.4.0.pre5.el6]
- Update to latest snapshot of icedtea7 2.4 forest
- Resolves: rhbz#917183

[1.7.0.9-2.4.0.pre4.3.el6]
- Updated  to icedtea 2.4.0.pre4,
- Rewritten (again) patch3 java-1.7.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#911530

[1.7.0.9-2.4.0.pre3.3.el6]
- Updated  to icedtea 2.4.0.pre3, updated!
- Rewritten patch3 java-1.7.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#911530

[1.7.0.9-2.4.0.pre2.3.el6]
- Removed testing
 - mauve was outdated and
 - jtreg was icedtea relict
- Updated  to icedtea 2.4.0.pre2, updated?
- Added java -Xshare:dump to post (see 513605) fo jitarchs
- Resolves: rhbz#911530

[1.7.0.11-2.4.0.2.el6]
- Unapplied but kept (for 2.3revert) patch110,  java-1.7.0-openjdk-nss-icedtea-e9c857dcb964.patch
- Added and applied patch113: java-1.7.0-openjdk-aes-update_reset.patch
- Added and applied patch114: java-1.7.0-openjdk-nss-tck.patch
- Added and applied patch115: java-1.7.0-openjdk-nss-split_results.patch
- NSS enabled by default - enable_nss set to 1
- rewritten patch109 - java-1.7.0-openjdk-nss-config-1.patch
- rewritten patch111 - java-1.7.0-openjdk-nss-config-2.patch
- Resolves: rhbz#831734

[1.7.0.11-2.4.0.1.el6]
- Rewritten patch105: java-1.7.0-openjdk-disable-system-lcms.patch
- Added jxmd and idlj to alternatives
- make executed with   DISABLE_INTREE_EC=true and UNLIMITED_CRYPTO=true
- Unapplied patch302 and deleted systemtap.patch
- buildver increased to 11
- icedtea_version set to 2.4.0
- Added and applied patch112 java-1.7.openjdk-doNotUseDisabledEcc.patch
- removed tmp-patches source tarball
- Added /lib/security/US_export_policy.jar and lib/security/local_policy.jar
- Disabled nss - enable_nss set to 0
- Resolves: rhbz#895034</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:02.831-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:13.126-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:21.238-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:25:18.916-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:25:18.916-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.8.0.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:130074"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.8.0.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:130073"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.8.0.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129571"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.8.0.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129843"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.8.0.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27590" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0589 -- git security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>git</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0589.html" ref_id="ELSA-2013-0589"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0308" ref_id="CVE-2013-0308"/>
        <description>[1.7.1-3.1]
- fix CVE-2013-0308

[1.7.1-3]
- fix CVE-2010-3906</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:38.154-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:12.460-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:20.588-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:37:41.802-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:37:41.802-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="git is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:129302"/>
          <criterion comment="emacs-git is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:130161"/>
          <criterion comment="emacs-git-el is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:130159"/>
          <criterion comment="git-all is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:129786"/>
          <criterion comment="git-cvs is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:130205"/>
          <criterion comment="git-daemon is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:130150"/>
          <criterion comment="git-email is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:130105"/>
          <criterion comment="git-gui is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:129887"/>
          <criterion comment="git-svn is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:130237"/>
          <criterion comment="gitk is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:129414"/>
          <criterion comment="gitweb is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:130206"/>
          <criterion comment="perl-Git is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:130134"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27589" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0528 -- ipa security, bug fix and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ipa</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0528.html" ref_id="ELSA-2013-0528"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4546" ref_id="CVE-2012-4546"/>
        <description>It was found that the current default configuration of IPA servers did not
publish correct CRLs (Certificate Revocation Lists). The default
configuration specifies that every replica is to generate its own CRL;
however, this can result in inconsistencies in the CRL contents provided to
clients from different Identity Management replicas. More specifically, if
a certificate is revoked on one Identity Management replica, it will not
show up on another Identity Management replica.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:43.502-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:12.271-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:20.382-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:20:08.736-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:20:08.736-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ipa is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:129698"/>
          <criterion comment="ipa-admintools is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:130200"/>
          <criterion comment="ipa-client is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:130173"/>
          <criterion comment="ipa-python is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:130257"/>
          <criterion comment="ipa-server is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:130295"/>
          <criterion comment="ipa-server-selinux is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:130207"/>
          <criterion comment="ipa-server-trust-ad is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:130178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27586" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1284 -- spice-gtk security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>spice-gtk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1284.html" ref_id="ELSA-2012-1284"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4425" ref_id="CVE-2012-4425"/>
        <description>[0.11-11.el6_3.1]
- Fix version for Z-stream
  Related: rhbz#854823

[0.11-12]
- Add patch fixing CVE-2012-3524
  Resolves: rhbz#854823</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:30.654-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:11.332-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:19.813-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:54:29.879-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:54:29.879-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="spice-gtk is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:131023"/>
          <criterion comment="spice-glib is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:130832"/>
          <criterion comment="spice-glib-devel is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:130958"/>
          <criterion comment="spice-gtk-devel is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:130659"/>
          <criterion comment="spice-gtk-python is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:131051"/>
          <criterion comment="spice-gtk-tools is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:131135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27584" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0270 -- jakarta-commons-httpclient security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0270.html" ref_id="ELSA-2013-0270"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5783" ref_id="CVE-2012-5783"/>
        <description>[1:3.1-0.7]
- Add missing connection hostname check against X.509 certificate name
- Resolves: CVE-2012-5783</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:33.007-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:10.761-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:19.519-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:27:03.954-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:27:03.954-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient is earlier than 0:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:130011"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 0:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:130060"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 0:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:130063"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 0:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:130346"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient is earlier than 0:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:130302"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 0:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:130393"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 0:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:130219"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 0:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:130432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27583" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0964 -- tomcat6 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0964.html" ref_id="ELSA-2013-0964"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2067" ref_id="CVE-2013-2067"/>
        <description>[0:6.0.24-57]
- Related: CVE-2013-2067 Session fixation

[0:6.0.24-56]
- Resolves: CVE-2013-2067 session fixation</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:20.728-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:10.464-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:19.397-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:39:58.649-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:39:58.649-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:129347"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:129303"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:129326"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:129418"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:129338"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:129358"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:128759"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:129163"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:129378"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27581" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0588 -- gnutls security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0588.html" ref_id="ELSA-2013-0588"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1619" ref_id="CVE-2013-1619"/>
        <description>[2.8.5-10.1]
- fix CVE-2013-1619 - fix TLS-CBC timing attack (#908238)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:37.103-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:09.969-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:19.083-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:31:21.784-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:31:21.784-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:129969"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:129816"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:129275"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129289"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129845"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:130053"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129979"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27579" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0902 -- cifs-utils security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cifs-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0902.html" ref_id="ELSA-2012-0902"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1586" ref_id="CVE-2012-1586"/>
        <description>[4.8.1-10]
- mount.cifs: don't allow unprivileged users to mount onto dirs they can't chdir into (bz 812782)

[4.8.1-9]
- cifs.upcall: use krb5_sname_to_principal to construct principal name (bz 805490)

[4.8.1-8]
- mount.cifs: add backupuid=/backupgid= mount options (bz 806337)

[4.8.1-7]
- RFE: Improve selection of SPNs with cifs.upcall (bz 748757)
- mount.cifs does not use KRB5_CONFIG (bz 748756)
[creates additional entries in /etc/mtab (bz 770004)]
- mount.cifs does not honor the uid/gid=username option, only the uid/gid=# option (bz 796463)

[4.8.1-6]
- undocumented mount.cifs options (bz 769923)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:16.589-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:09.429-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:18.750-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:44:47.104-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:44:47.104-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="cifs-utils is earlier than 0:4.8.1-10.el6" test_ref="oval:org.mitre.oval:tst:131300"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27578" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0273 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0273.html" ref_id="ELSA-2013-0273"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0169" ref_id="CVE-2013-0169"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1486" ref_id="CVE-2013-1486"/>
        <description>[1:1.6.0.0-1.56.1.11.8]
- Rebuild with updated sources
- Resolves: rhbz#911524

[1:1.6.0.0-1.55.1.11.8]
- Updated to icedtea6 1.11.8
- Removed patch9   7201064.patch
- Removed patch10   8005615.patch
- Removed  not-applied patch 6664509.patch
- Removed mauve as deadly outdated and run on QA
  -  jtreg kept, useless, but working
- Resolves: rhbz#911524</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:33.742-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:09.253-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:18.613-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:40:02.664-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:40:02.664-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:130434"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:130267"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:130191"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:130398"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:129598"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27577" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0580 -- cups security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0580.html" ref_id="ELSA-2013-0580"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5519" ref_id="CVE-2012-5519"/>
        <description>[1:1.4.2-50:.4]
- Added BrowseLDAPCACertFile and PrintcapGUI to restricted options
  list.

[1:1.4.2-50:.3]
- Fix for CVE-2012-5519 patch: handle blacklisted lines that have no
  value part gracefully.

[1:1.4.2-50:.2]
- Added documentation for new CVE-2012-5519 option.

[1:1.4.2-50:.1]
- Applied patch to fix CVE-2012-5519 (privilege escalation for users
  in SystemGroup or with equivalent polkit permission).  This prevents
  HTTP PUT requests with paths under /admin/conf/ other than that for
  cupsd.conf, and also prevents such requests altering certain
  configuration directives such as PageLog and FileDevice (bug #875898).

[1:1.4.2-50]
- Fixed LDAP browsing issues (bug #870386).

[1:1.4.2-49]
- Avoid 'forbidden' error when moving job between queues via web UI
  (bug #834445).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:45.028-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:08.947-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:18.416-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:59:36.033-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:59:36.033-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups is earlier than 0:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:130242"/>
            <criterion comment="cups-devel is earlier than 0:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:130268"/>
            <criterion comment="cups-libs is earlier than 0:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:130183"/>
            <criterion comment="cups-lpd is earlier than 0:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:129592"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:130033"/>
            <criterion comment="cups-devel is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:130233"/>
            <criterion comment="cups-libs is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:129667"/>
            <criterion comment="cups-lpd is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:130027"/>
            <criterion comment="cups-php is earlier than 0:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:130253"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27576" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0858 -- xerces-j2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xerces-j2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0858.html" ref_id="ELSA-2011-0858"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625" ref_id="CVE-2009-2625"/>
        <description>[0:2.7.1-12.6]
- Add xerces-j2-CVE-2009-2625.patch
- Resolves: rhbz#690931 CVE-2009-2625</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:38.382-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:08.652-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:18.183-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:23:14.999-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:23:14.999-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xerces-j2 is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:133469"/>
          <criterion comment="xerces-j2-demo is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:133777"/>
          <criterion comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:133721"/>
          <criterion comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:133564"/>
          <criterion comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:133372"/>
          <criterion comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:133562"/>
          <criterion comment="xerces-j2-scripts is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:132813"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27575" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0526 -- automake security update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>automake</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0526.html" ref_id="ELSA-2013-0526"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3386" ref_id="CVE-2012-3386"/>
        <description>[1.11.1-4]
- remove BR dependency on java-devel-openjdk

[1.11.1-3]
- fix for CVE-2012-3386 -- 'make distcheck' was making the directory distdir
  world-readable (#848469)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:50.922-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:08.381-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:18.028-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:44:02.338-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:44:02.338-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="automake is earlier than 0:1.11.1-4.el6" test_ref="oval:org.mitre.oval:tst:130198"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27574" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0590 -- nss-pam-ldapd security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nss-pam-ldapd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0590.html" ref_id="ELSA-2013-0590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0288" ref_id="CVE-2013-0288"/>
        <description>[0.7.5-18.1]
- Apply upstream r1926 to resolve FD_SET array index error
- Resolves: rhbz#915361</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:04.537-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:08.133-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:17.888-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:22:07.227-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:22:07.227-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="nss-pam-ldapd is earlier than 0:0.7.5-18.1.el6_4" test_ref="oval:org.mitre.oval:tst:129929"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27573" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0250 -- elinks security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>elinks</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0250.html" ref_id="ELSA-2013-0250"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4545" ref_id="CVE-2012-4545"/>
        <description>[0.12-0.21.pre5]
- do not delegate GSSAPI credentials (CVE-2012-4545)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:46.701-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:07.881-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:17.765-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:52:14.207-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:52:14.207-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="elinks is earlier than 0:0.11.1-8.el5_9" test_ref="oval:org.mitre.oval:tst:129956"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="elinks is earlier than 0:0.12-0.21.pre5.el6_3" test_ref="oval:org.mitre.oval:tst:130340"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27569" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0605 -- java-1.6.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0605.html" ref_id="ELSA-2013-0605"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1493" ref_id="CVE-2013-1493"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0809" ref_id="CVE-2013-0809"/>
        <description>[1:1.6.0.0-1.57.1.11.9]
- Updated to icedtea6 1.11.9
- Resolves: rhbz#917179</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:35.019-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:06.660-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:16.962-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:30:03.848-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:30:03.848-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:129946"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:129825"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:130067"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:129985"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:129249"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27568" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0815 -- httpd security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0815.html" ref_id="ELSA-2013-0815"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4558" ref_id="CVE-2012-4558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1862" ref_id="CVE-2013-1862"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3499" ref_id="CVE-2012-3499"/>
        <description>[2.2.15-28.0.1.el6_4]
- replace index.html with Oracle's index page oracle_index.html
  update vstring in specfile

[2.2.15-28]
- mod_rewrite: add security fix for CVE-2013-1862 (#953729)

[2.2.15-27]
- add security fixes for CVE-2012-3499, CVE-2012-4558 (#915883, #915884)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:46.665-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:06.163-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:16.790-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:17:40.410-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:17:40.410-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-78.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129685"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129593"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129524"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-78.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129474"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129561"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129661"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129600"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129643"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-28.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129014"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27567" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1531 -- qemu-kvm security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1531.html" ref_id="ELSA-2011-1531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2527" ref_id="CVE-2011-2527"/>
        <description>[qemu-kvm-0.12.1.2-2.209.el6]
- kvm-hda-do-not-mix-output-and-input-streams-RHBZ-740493-v2.patch [bz#740493]
- kvm-hda-do-not-mix-output-and-input-stream-states-RHBZ-740493-v2.patch [bz#740493]
- kvm-intel-hda-fix-stream-search.patch [bz#740493]
- Resolves: bz#740493
  (audio playing doesn't work when sound recorder is opened)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:24.078-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:05.863-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:16.705-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.209.el6" test_ref="oval:org.mitre.oval:tst:133112"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27566" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1426 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1426.html" ref_id="ELSA-2012-1426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1568" ref_id="CVE-2012-1568"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2133" ref_id="CVE-2012-2133"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3400" ref_id="CVE-2012-3400"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3511" ref_id="CVE-2012-3511"/>
        <description>[2.6.32-279.14.1.el6]
- [usb] usbhid: Fix use-after-free in USBHID (James Paradis) [864827 857518]
- [usb] Add kernel parameter to force io_watchdog for Intel EHCI HCD (James Paradis) [865713 846024]
- [block] Fix hanging kernel threads in blk_execute_rq() (James Paradis) [865308 855984]
- [mm] hugetlb: do not use vma_hugecache_offset() for vma_prio_tree_foreach (Frederic Weisbecker) [843034 843035] {CVE-2012-2133}
- [mm] hugepages: fix use after free bug in 'quota' handling (Frederic Weisbecker) [843034 843035] {CVE-2012-2133}
- [mm] hugetlb: fix pgoff computation when unmapping page from vma (Frederic Weisbecker) [843034 843035] {CVE-2012-2133}
- [mm] hugetlb: fix ENOSPC returned by handle_mm_fault() (Frederic Weisbecker) [843034 843035] {CVE-2012-2133}
- [fs] gfs2: Write out dirty inode metadata in delayed deletes (Frantisek Hrbata) [859326 748827]
- [usb] core: Fix device removal race condition (James Paradis) [864821 849188]
- [mm] x86_32: fix SHLIB_BASE address typo (Aristeu S. Rozanski F) [804955 804956] {CVE-2012-1568}
- [hid] hidraw: fix window in hidraw_release (Don Zickus) [841824 839973]
- [hid] hidraw: protect hidraw_disconnect() better (Don Zickus) [841824 839973]
- [hid] hidraw: remove excessive _EMERG messages from hidraw (Don Zickus) [841824 839973]
- [hid] hidraw: fix hidraw_disconnect() (Don Zickus) [841824 839973]
- [hid] fix a NULL pointer dereference in hidraw_write (Don Zickus) [841824 839973]
- [hid] fix a NULL pointer dereference in hidraw_ioctl (Don Zickus) [841824 839973]
- [hid] remove BKL from hidraw (Don Zickus) [841824 839973]
- [mm] x86_32: randomize SHLIB_BASE (Aristeu Rozanski) [804955 804956] {CVE-2012-1568}
- [block] fix up use after free in __blkdev_get (Jeff Moyer) [853943 847838]
- [scsi] remove no longer valid BUG_ON in scsi_lld_busy (Jeff Garzik) [860640 842881]
- [scsi] fix NULL request_queue in scsi_requeue_run_queue() (Jeff Garzik) [860640 842881]
- [net] svcrpc: fix BUG() in svc_tcp_clear_pages (J. Bruce Fields) [856106 769045]
- [scsi] lpfc: Fixed SCSI device reset escalation (Rob Evers) [861390 827566]
- [scsi] lpfc: Fix abort status (Rob Evers) [861390 827566]
- [kernel] cgroup: add cgroup_root_mutex (Frederic Weisbecker) [858954 844531]
- [mm] Hold a file reference in madvise_remove (Jerome Marchand) [849738 849739] {CVE-2012-3511}
- [base] driver-core: fix device_register race (Rob Evers) [860784 833098]
- [netdrv] e1000e: drop check of RXCW.CW to eliminate link going up and down (Dean Nelson) [857055 847310]
- [scsi] be2iscsi: Format the MAC_ADDR with sysfs (Rob Evers) [863147 827594]
- [usb] usbdevfs: Add a USBDEVFS_GET_CAPABILITIES ioctl (Don Zickus) [841667 828271]
- [fs] udf: fix retun value on error path in udf_load_logicalvol (Nikola Pajkovsky) [843142 843143] {CVE-2012-3400}
- [fs] udf: Improve table length check to avoid possible overflow (Nikola Pajkovsky) [843142 843143] {CVE-2012-3400}
- [fs] udf: Fortify loading of sparing table (Nikola Pajkovsky) [843142 843143] {CVE-2012-3400}
- [fs] udf: Avoid run away loop when partition table length is corrupted (Nikola Pajkovsky) [843142 843143] {CVE-2012-3400}
- [fs] udf: Use 'ret' instead of abusing 'i' in udf_load_logicalvol() (Nikola Pajkovsky) [843142 843143] {CVE-2012-3400}
- [netdrv] bnx2x: Add remote-fault link detection (Michal Schmidt) [852450 814877]
- [net] sunrpc: svc_xprt sends on closed socket should stop immediately (J. Bruce Fields) [853257 849702]
- [mm] Never OOM kill tasks outside of memory cgroup when memory.limit_in_bytes is exceeded by a Transparent Huge Page (Larry Woodman) [860942 811255]
- [powerpc] pseries: Support lower minimum entitlement for virtual processors (Steve Best) [860165 822651]
- [usbhid] hiddev: Consolidate device existence checks in hiddev_ioctl (Don Zickus) [841824 839973]
- [usbhid] hiddev: Fix race between disconnect and hiddev_ioctl (Don Zickus) [841824 839973]
- [usbhid] hiddev: protect against disconnect/NULL-dereference race (Don Zickus) [841824 839973]
- [crypto] algapi: Move larval completion into algboss (Herbert Xu) [854476 832135]
- [fs] xfs: disable xfsaild idle mode (Brian Foster) [860787 813137]
- [fs] xfs: fix the logspace waiting algorithm (Brian Foster) [860787 813137]
- [fs] xfs: add AIL pushing tracepoints (Brian Foster) [860787 813137]
- [fs] xfs: force the log if we encounter pinned buffers in .iop_pushbuf (Brian Foster) [860787 813137]
- [fs] xfs: do not update xa_last_pushed_lsn for locked items (Brian Foster) [860787 813137]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:39.556-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:05.287-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:16.431-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:24:44.231-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:24:44.231-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:130692"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:130869"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:130543"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:130342"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:130925"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:130637"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:130886"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:130748"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:130737"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27564" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0897 -- mesa security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mesa</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0897.html" ref_id="ELSA-2013-0897"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1872" ref_id="CVE-2013-1872"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1993" ref_id="CVE-2013-1993"/>
        <description>[9.0-0.8.3]
- CVE-2013-1872: Updated patch with testing from upstream (#963063)

[9.0-0.8.2]
- CVE-2013-1872: Updated patch from upstream (#963063)

[9.0-0.8.1]
- CVE-2013-1872: Updated patch (#963063)

[9.0-0.8]
- CVE-2013-1872: memory corruption oob read/write on intel (#963063)
- CVE-2013-1993: interger overflows in protocol handling (#961613)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:42.940-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:04.838-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:16.076-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:37:12.524-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:37:12.524-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mesa is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:129396"/>
          <criterion comment="glx-utils is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:129401"/>
          <criterion comment="mesa-demos is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:129528"/>
          <criterion comment="mesa-dri-drivers is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:129444"/>
          <criterion comment="mesa-dri-filesystem is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:129160"/>
          <criterion comment="mesa-libGL is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:128811"/>
          <criterion comment="mesa-libGL-devel is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:129133"/>
          <criterion comment="mesa-libGLU is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:129503"/>
          <criterion comment="mesa-libGLU-devel is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:129545"/>
          <criterion comment="mesa-libOSMesa is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:128912"/>
          <criterion comment="mesa-libOSMesa-devel is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:129492"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27562" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0272 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0272.html" ref_id="ELSA-2013-0272"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0775" ref_id="CVE-2013-0775"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0776" ref_id="CVE-2013-0776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0780" ref_id="CVE-2013-0780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0782" ref_id="CVE-2013-0782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0783" ref_id="CVE-2013-0783"/>
        <description>[17.0.3-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.3-1]
- Update to 17.0.3 ESR

[17.0.2-2]
- Update to 17.0.2 ESR

[17.0-2]
- Update to 17.0 ESR

[17.0b2-0.1]
- Update to 17.0b2

[17.0b1-0.1]
- Rebase to 17 beta 1</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:56.621-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:04.175-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:15.710-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:33:10.497-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:33:10.497-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130216"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130182"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27561" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0571 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0571.html" ref_id="ELSA-2012-0571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4086" ref_id="CVE-2011-4086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1601" ref_id="CVE-2012-1601"/>
        <description>[2.6.32-220.17.1.el6]
- [scsi] fcoe: Do not switch context in vport_delete callback (Neil Horman) [809388 806119]

[2.6.32-220.16.1.el6]
- Revert: [x86] Ivy Bridge kernel rdrand support (Jay Fenlason) [800268 696442]

[2.6.32-220.15.1.el6]
- [net] SUNRPC: We must not use list_for_each_entry_safe() in rpc_wake_up() (Steve Dickson) [811299 809928]
- [char] ipmi: Increase KCS timeouts (Matthew Garrett) [806906 803378]
- [kernel] sched: Fix ancient race in do_exit() (Frantisek Hrbata) [805457 784758]
- [scsi] sd: Unmap discard alignment needs to be converted to bytes (Mike Snitzer) [810322 805519]
- [scsi] sd: Fix VPD buffer allocations (Mike Snitzer) [810322 805519]
- [x86] Ivy Bridge kernel rdrand support (Jay Fenlason) [800268 696442]
- [scsi] fix system lock up from scsi error flood (Frantisek Hrbata) [809378 800555]
- [sound] ALSA: pcm midlevel code - add time check for (Jaroslav Kysela) [801329 798984]
- [pci] Add pcie_hp=nomsi to disable MSI/MSI-X for pciehp driver (hiro muneda) [807426 728852]
- [sound] ALSA: enable OSS emulation layer for PCM and mixer (Jaroslav Kysela) [812960 657291]
- [scsi] qla4xxx: Fixed BFS with sendtargets as boot index (Chad Dupuis) [803881 722297]
- [fs] nfs: Additional readdir cookie loop information (Steve Dickson) [811135 770250]
- [fs] NFS: Fix spurious readdir cookie loop messages (Steve Dickson) [811135 770250]
- [x86] powernow-k8: Fix indexing issue (Frank Arnold) [809391 781566]
- [x86] powernow-k8: Avoid Pstate MSR accesses on systems supporting CPB (Frank Arnold) [809391 781566]
- [redhat] spec: Add python-perf-debuginfo subpackage (Josh Boyer) [806859 806859]

[2.6.32-220.14.1.el6]
- [net] fix vlan gro path (Jiri Pirko) [810454 720611]
- [virt] VMX: vmx_set_cr0 expects kvm->srcu locked (Marcelo Tosatti) [808206 807507] {CVE-2012-1601}
- [virt] KVM: Ensure all vcpus are consistent with in-kernel irqchip settings (Marcelo Tosatti) [808206 807507] {CVE-2012-1601}
- [scsi] fcoe: Move destroy_work to a private work queue (Neil Horman) [809388 806119]
- [fs] jbd2: clear BH_Delay &amp; BH_Unwritten in journal_unmap_buffer (Eric Sandeen) [749727 748713] {CVE-2011-4086}
- [net] af_iucv: offer new getsockopt SO_MSGSIZE (Hendrik Brueckner) [804547 786997]
- [net] af_iucv: performance improvements for new HS transport (Hendrik Brueckner) [804548 786996]
- [s390x] af_iucv: remove IUCV-pathes completely (Hendrik Brueckner) [807158 786960]
- [x86] iommu/amd: Fix wrong shift direction (Don Dutile) [809376 781531]
- [x86] iommu/amd: Don't use MSI address range for DMA addresses (Don Dutile) [809374 781524]
- [fs] NFSv4: Further reduce the footprint of the idmapper (Steve Dickson) [802852 730045]
- [fs] NFSv4: Reduce the footprint of the idmapper (Steve Dickson) [802852 730045]
- [scsi] fcoe: Make fcoe_transport_destroy a synchronous operation (Neil Horman) [809372 771251]
- [net] ipv4: Constrain UFO fragment sizes to multiples of 8 bytes (Jiri Benc) [809104 797731]
- [net] ipv4: Don't use ufo handling on later transformed packets (Jiri Benc) [809104 797731]
- [net] udp: Add UFO to NETIF_F_GSO_SOFTWARE (Jiri Benc) [809104 797731]
- [fs] nfs: Try using machine credentials for RENEW calls (Sachin Prabhu) [806205 795441]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:16.363-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:03.798-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:15.421-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:48:46.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:48:46.567-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:132003"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:132200"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:131580"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:131287"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:132085"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:132110"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:132233"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:132250"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:132194"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27559" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0899 -- openldap security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0899.html" ref_id="ELSA-2012-0899"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1164" ref_id="CVE-2012-1164"/>
        <description>[2.4.23-26]
- fix: MozNSS CA cert dir does not work together with PEM CA cert file (#818844)
- fix: memory leak: def_urlpre is not freed (#816168)
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)

[2.4.23-25]
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)

[2.4.23-24]
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)
- fix: memberof overlay on the frontend database causes server segfault (#730745)

[2.4.23-23]
- security fix: CVE-2012-1164: assertion failure by processing search queries
  requesting only attributes for particular entry (#813162)

[2.4.23-22]
- fix: libraries leak memory when following referrals (#807363)

[2.4.23-21]
- fix: ldapsearch crashes with invalid parameters (#743781)
- fix: replication (syncrepl) with TLS causes segfault (#783445)
- fix: openldap server in MirrorMode sometimes fails to resync via syncrepl (#784211)
- use portreserve to reserve LDAPS port (636/tcp+udp) (#790687)
- fix: missing options in manual pages of client tools (#745470)
- fix: SASL_NOCANON option missing in ldap.conf manual page (#732916)
- fix: slapd segfaults when certificate key cannot be loaded (#796808)
- Jan Synacek &lt;jsynacek@redhat.com>
  + fix: overlay constraint with count option work bad with modify operation (#742163)
  + fix: Default SSL certificate bundle is not found by openldap library (#742023)
  + fix: Duplicate close() calls in OpenLDAP (#784203)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:26.189-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:03.382-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:15.137-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:58:19.795-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:58:19.795-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openldap is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:131479"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:130807"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:131696"/>
          <criterion comment="openldap-servers is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:131553"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:131772"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27556" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0743 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0743.html" ref_id="ELSA-2012-0743"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0044" ref_id="CVE-2012-0044"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1179" ref_id="CVE-2012-1179"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2119" ref_id="CVE-2012-2119"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2123" ref_id="CVE-2012-2123"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2137" ref_id="CVE-2012-2137"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2372" ref_id="CVE-2012-2372"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2373" ref_id="CVE-2012-2373"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2121" ref_id="CVE-2012-2121"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2136" ref_id="CVE-2012-2136"/>
        <description>[2.6.32-220.23.1.el6]
- [net] bond: Make LRO flag follow slave settings (Neil Horman) [831176 794647]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:16.026-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:02.603-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:14.266-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:40:59.024-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:40:59.024-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:131802"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:130990"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:131015"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:131715"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:131737"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:132016"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:131439"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:131778"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:131024"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27555" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2523 -- Unbreakable Enterprise kernel security and bugfix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2523.html" ref_id="ELSA-2013-2523"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4542" ref_id="CVE-2012-4542"/>
        <description>[2.6.39-400.23.1]
- Parallel mtrr init between cpus (Zhenzhong Duan) [Orabug: 16777774]
- Merge tag 'v2.6.39-400.21.1.16748891' of git://ca-git.us.oracle.com/linux-uek-2.6.39-ofed into uek-2.6.39-400 (Maxim Uvarov) [Orabug: 16748891]
- xen-blkfront: use a different scatterlist for each request (Roger Pau Monne)
- Fix EN driver to work with newer FWs based on latest mlx4_core (Yuval Shaia) [Orabug: 16748891]

[2.6.39-400.22.1]
- block: default SCSI command filter does not accomodate commands overlap across device classes (Jamie Iles) [Orabug: 16387137] {CVE-2012-4542}
- Merge tag 'v2.6.39-400.21.1#bug16684527' of git://ca-git.us.oracle.com/linux-joejin-public into uek-2.6.39-400_errata (Maxim Uvarov) [Orabug: 16684527]
- KVM: x86: Convert MSR_KVM_SYSTEM_TIME to use gfn_to_hva_cache functions (CVE-2013-1797) (Andy Honig) [Orabug: 16711660] {CVE-2013-1797}
- Bluetooth: Fix incorrect strncpy() in hidp_setup_hid() (Anderson Lizardo) [Orabug: 16711065] {CVE-2013-0349}
- USB: io_ti: Fix NULL dereference in chase_port() (Wolfgang Frisch) [Orabug: 16425358] {CVE-2013-1774}
- keys: fix race with concurrent install_user_keyrings() (David Howells) [Orabug: 16493354] {CVE-2013-1792}
- KVM: Fix bounds checking in ioapic indirect register reads (CVE-2013-1798) (Andy Honig) [Orabug: 16710951] {CVE-2013-1798}
- KVM: x86: fix for buffer overflow in handling of MSR_KVM_SYSTEM_TIME (CVE-2013-1796) (Andy Honig) [Orabug: 16710806] {CVE-2013-1796}
- tmpfs: fix use-after-free of mempolicy object (Greg Thelen) [Orabug: 16515833] {CVE-2013-1767}
- procfs: do not confuse jiffies with cputime64_t (Andreas Schwab) [Orabug: 16673925]
- procfs: do not overflow get_{idle,iowait}_time for nohz (Michal Hocko) [Orabug: 16673925]
- xen/evtchn: Handle VIRQ_TIMER before any other hardirq in event loop. (Keir Fraser) [Orabug: 16093126]
- Fix device removal NULL pointer dereference (Joe Jin) [Orabug: 16684527]
- put stricter guards on queue dead checks (James Bottomley) [Orabug: 16684527]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:42.829-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:02.466-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:14.088-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129253"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129386"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129494"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129344"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129462"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.23.1.el5uek" test_ref="oval:org.mitre.oval:tst:129422"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129653"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129649"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129619"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129437"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129639"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.23.1.el6uek" test_ref="oval:org.mitre.oval:tst:129562"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27554" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0827 -- openswan security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0827.html" ref_id="ELSA-2013-0827"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2053" ref_id="CVE-2013-2053"/>
        <description>[2.6.32-20]
Resolves: #960234 - CVE-2013-2053</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:51.991-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:02.280-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:13.953-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:45:04.378-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:45:04.378-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:129351"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:129306"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:129450"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:128914"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27553" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0276 -- libvirt security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0276.html" ref_id="ELSA-2013-0276"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3411" ref_id="CVE-2012-3411"/>
        <description>[libvirt-0.10.2-18.0.1.el6]

- Replace docs/et.png in tarball with blank image



[0.10.2-18]

- rpc: Fix crash on error paths of message dispatching (CVE-2013-0170)

- spec: Disable libssh2 support (rhbz#513363)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:45.937-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:02.185-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:13.853-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:11:37.537-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:11:37.537-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.10.2-18.0.1.el6" test_ref="oval:org.mitre.oval:tst:129749"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-18.0.1.el6" test_ref="oval:org.mitre.oval:tst:130215"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-18.0.1.el6" test_ref="oval:org.mitre.oval:tst:130307"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-18.0.1.el6" test_ref="oval:org.mitre.oval:tst:130262"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27552" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0836 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0836.html" ref_id="ELSA-2011-0836"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3858" ref_id="CVE-2010-3858"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1598" ref_id="CVE-2011-1598"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1748" ref_id="CVE-2011-1748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1770" ref_id="CVE-2011-1770"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1771" ref_id="CVE-2011-1771"/>
        <description>[2.6.32-131.2.1.el6]
- [kernel] lib/vsprintf.c: add %pU to print UUID/GUIDs (Frantisek Hrbata) [704280 700299]
- [scsi] megaraid_sas: Driver only report tape drive, JBOD and logic drives (Tomas Henzl) [704601 619422]

[2.6.32-131.1.1.el6]
- [net] dccp: handle invalid feature options length (Jiri Pirko) [703012 703013] {CVE-2011-1770}
- [fs] cifs: check for private_data before trying to put it (Jeff Layton) [703017 702642] {CVE-2011-1771}
- [net] can: add missing socket check in can/raw and can/bcm release (Jiri Pirko) [698482 698483] {CVE-2011-1748 CVE-2011-1598}
- [netdrv] ixgbe: do not clear FCoE DDP error status for received ABTS (Andy Gospodarek) [704011 695966]
- [netdrv] ixgbe: DCB remove ixgbe_fcoe_getapp routine (Andy Gospodarek) [704002 694358]
- [fs] setup_arg_pages: diagnose excessive argument size (Oleg Nesterov) [645228 645229] {CVE-2010-3858}
- [scsi] bfa: change tech-preview to cover all cases (Rob Evers) [704014 703251]
- [scsi] bfa: driver version update (Rob Evers) [704282 703265]
- [scsi] bfa: kdump fix (Rob Evers) [704282 703265]
- [scsi] bfa: firmware download fix (Rob Evers) [704282 703265]
- [netdrv] bna: fix memory leak during RX path cleanup (Ivan Vecera) [704000 698625]
- [netdrv] bna: fix for clean fw re-initialization (Ivan Vecera) [704000 698625]
- [scsi] ipr: improve interrupt service routine performance (Steve Best) [704009 696754]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:17.200-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:01.924-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:13.628-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:04:45.098-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:04:45.098-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:133118"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:133541"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:133557"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:133156"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:133410"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:133672"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:133365"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:133582"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27551" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0275 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0275.html" ref_id="ELSA-2013-0275"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1485" ref_id="CVE-2013-1485"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1484" ref_id="CVE-2013-1484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1486" ref_id="CVE-2013-1486"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0169" ref_id="CVE-2013-0169"/>
        <description>[1.7.0.9-2.3.7.1.0.2.el6_3]
- Increase release number and rebuild.

[1.7.0.9-2.3.7.1.0.1.el6_3]
- Update DISTRO_NAME in specfile

[1.7.0.9-2.3.7.1.el6_3]
- Updated main source tarball
- Resolves: rhbz#911529

[1.7.0.9-2.3.7.0.el6_3]
- Removed patch1000 sec-2013-02-01-8005615.patch
- Removed patch1001 sec-2013-02-01-8005615-sync_with_jdk7u.patch
- Removed patch1010 sec-2013-02-01-7201064.patch
- Removed testing
 - mauve was outdated and
 - jtreg was icedtea relict
- Updated  to icedtea 2.3.7
- Added java -Xshare:dump to post (see 513605) fo jitarchs
- Resolves: rhbz#911529</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:55.345-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:01.653-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:13.348-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:49:00.580-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:49:00.580-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130282"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129948"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130151"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129977"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.7.1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130448"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130290"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130327"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130384"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130410"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.7.1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130090"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27550" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2020 -- Unbreakable Enterprise kernel security and bugfix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2020.html" ref_id="ELSA-2012-2020"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2123" ref_id="CVE-2012-2123"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2136" ref_id="CVE-2012-2136"/>
        <description>kernel-uek: [2.6.32-300.27.1.el6uek] - net: sock: validate data_len before
          allocating skb (Jason Wang) [Bugdb: 13966]{CVE-2012-2136} - fcaps: clear the same
          personality flags as suid when fcaps are used (Eric Paris) [Bugdb: 13966] {CVE-2012-2123}
          - Revert 'nfs: when attempting to open a directory, fall back on normal lookup (Todd
          Vierling) [Orabug 14141154] [2.6.32-300.26.1.el6uek] - mptsas: do not call __mptsas_probe
          in kthread (Maxim Uvarov) [Orabug: 14175509] - mm: check if any page in a pageblock is
          reserved before marking it MIGRATE_RESERVE (Maxim Uvarov) [Orabug: 14073214] - mm: reduce
          the amount of work done when updating min_free_kbytes (Mel Gorman) [Orabug: 14073214] -
          vmxnet3: Updated to el6-u2 (Guangyu Sun) [Orabug: 14027961] - xen: expose host uuid via
          sysfs. (Zhigang Wang) - sched: Fix cgroup movement of waking process (Daisuke Nishimura)
          [Orabug: 13946210] - sched: Fix cgroup movement of newly created process (Daisuke
          Nishimura) [Orabug: 13946210] - sched: Fix cgroup movement of forking process (Daisuke
          Nishimura) [Orabug: 13946210] - x86, boot: Wait for boot cpu to show up if nr_cpus limit
          is about to hit (Zhenzhong Duan) [Orabug: 13629087] - smp: Use nr_cpus= to set nr_cpu_ids
          early (Zhenzhong Duan) [Orabug: 13629087] - net: ipv4: relax AF_INET check in bind()
          (Maxim Uvarov) [Orabug: 14054411] ofa-2.6.32-300.27.1.el6uek: [1.5.1-4.0.58] - Add Patch
          158-169</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:38.809-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:01.334-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:13.137-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36582 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:38.710-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:23.976-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131839"/>
            <criterion comment="mlnx_en-2.6.32-300.27.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131914"/>
            <criterion comment="ofa-2.6.32-300.27.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131604"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131880"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131574"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131692"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131561"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:131931"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.27.1.el5uek" test_ref="oval:org.mitre.oval:tst:130973"/>
            <criterion comment="mlnx_en-2.6.32-300.27.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:131822"/>
            <criterion comment="ofa-2.6.32-300.27.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131897"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131849"/>
            <criterion comment="mlnx_en-2.6.32-300.27.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131765"/>
            <criterion comment="ofa-2.6.32-300.27.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131319"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131936"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131865"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131797"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131934"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131520"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.27.1.el6uek" test_ref="oval:org.mitre.oval:tst:131482"/>
            <criterion comment="mlnx_en-2.6.32-300.27.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131852"/>
            <criterion comment="ofa-2.6.32-300.27.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131719"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27549" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3095 -- docker security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>docker</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3095.html" ref_id="ELSA-2014-3095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6407" ref_id="CVE-2014-6407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6408" ref_id="CVE-2014-6408"/>
        <description>[1.3.2-1.0.1]
- Rename requirement of docker-io-pkg-devel in %package devel as docker-pkg-devel
- Restore SysV init scripts for Oracle Linux 6
- Require Oracle Unbreakable Enterprise Kernel Release 3 or higher
- Rename as docker.
- Re-enable btrfs graphdriver support

[1.3.2-1]
- Update source to 1.3.2 from https://github.com/docker/docker/releases/tag/v1.3.2
  Prevent host privilege escalation from an image extraction vulnerability (CVE-2014-6407).
  Prevent container escalation from malicious security options applied to images (CVE-2014-6408).
  The '--insecure-registry' flag of the 'docker run' command has undergone several refinements and additions.
  You can now specify a sub-net in order to set a range of registries which the Docker daemon will consider insecure.
  By default, Docker now defines 'localhost' as an insecure registry.
  Registries can now be referenced using the Classless Inter-Domain Routing (CIDR) format.
  When mirroring is enabled, the experimental registry v2 API is skipped.

[1.3.1-2]
- Remove pandoc from build reqs

[1.3.1-1]
- update to v1.3.1

[1.3.0-1]
- Resolves: rhbz#1153936 - update to v1.3.0
- iptables=false => ip-masq=false

[1.2.0-3]
- Resolves: rhbz#1139415 - correct path for bash completion
    /usr/share/bash-completion/completions
- sysvinit script update as per upstream commit
    640d2ef6f54d96ac4fc3f0f745cb1e6a35148607
- dont own dirs for vim highlighting, bash completion and udev

[1.2.0-2]
- Resolves: rhbz#1145660 - support /etc/sysconfig/docker-storage
  From: Colin Walters &lt;walters@redhat.com>
- patch to ignore selinux if its disabled
  https://github.com/docker/docker/commit/9e2eb0f1cc3c4ef000e139f1d85a20f0e00971e6
  From: Dan Walsh &lt;dwalsh@redhat.com>
- Resolves: rhbz#1139415 - correct path for bash completion
- init script waits upto 5 mins before terminating daemon

[1.2.0-1]
- Resolves: rhbz#1132824 - update to v1.2.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:21.967-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:10.276-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:10.978-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="docker is earlier than 0:1.3.2-1.0.1.el6" test_ref="oval:org.mitre.oval:tst:135930"/>
            <criterion comment="docker-devel is earlier than 0:1.3.2-1.0.1.el6" test_ref="oval:org.mitre.oval:tst:135038"/>
            <criterion comment="docker-pkg-devel is earlier than 0:1.3.2-1.0.1.el6" test_ref="oval:org.mitre.oval:tst:135623"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="docker is earlier than 0:1.3.2-1.0.1.el7" test_ref="oval:org.mitre.oval:tst:135780"/>
            <criterion comment="docker-devel is earlier than 0:1.3.2-1.0.1.el7" test_ref="oval:org.mitre.oval:tst:136017"/>
            <criterion comment="docker-pkg-devel is earlier than 0:1.3.2-1.0.1.el7" test_ref="oval:org.mitre.oval:tst:135761"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27548" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0426 -- spice-xpi security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>spice-xpi</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0426.html" ref_id="ELSA-2011-0426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0012" ref_id="CVE-2011-0012"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1179" ref_id="CVE-2011-1179"/>
        <description>[2.4-1.el6_0.2]
- Fix security vulnerability CVE-2011-0012 (rhbz#639869)
  Resolves: rhbz#639870

[2.4-1.el6_0.1]
- Fix security vulnerability CVE-2011-1179 (rhbz#689931)
  Resolves: rhbz#689932</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:58.816-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:01.023-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.992-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:00:52.108-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:00:52.108-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="spice-xpi is earlier than 0:2.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:133834"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27547" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1363 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1363.html" ref_id="ELSA-2012-1363"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5166" ref_id="CVE-2012-5166"/>
        <description>[32:9.8.2-0.10.rc1.5]
- fix CVE-2012-5166</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:29.441-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:00.809-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.888-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:51:51.886-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:51:51.886-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130730"/>
            <criterion comment="bind-chroot is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131081"/>
            <criterion comment="bind-devel is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130950"/>
            <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131033"/>
            <criterion comment="bind-libs is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130920"/>
            <criterion comment="bind-sdb is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130711"/>
            <criterion comment="bind-utils is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:131055"/>
            <criterion comment="caching-nameserver is earlier than 0:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:130760"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:130220"/>
            <criterion comment="bind-chroot is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:131162"/>
            <criterion comment="bind-devel is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:131161"/>
            <criterion comment="bind-libs is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:130877"/>
            <criterion comment="bind-sdb is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:131151"/>
            <criterion comment="bind-utils is earlier than 0:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:130196"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27546" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1139 -- bind-dyndb-ldap security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind-dyndb-ldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1139.html" ref_id="ELSA-2012-1139"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3429" ref_id="CVE-2012-3429"/>
        <description>[1.1.0-0.9.b1.1]
- fix CVE-2012-3429</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:19.954-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:00.641-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.805-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:53:45.787-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:53:45.787-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="bind-dyndb-ldap is earlier than 0:1.1.0-0.9.b1.el6_3.1" test_ref="oval:org.mitre.oval:tst:130997"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27545" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2525 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2525.html" ref_id="ELSA-2013-2525"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6542" ref_id="CVE-2012-6542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1929" ref_id="CVE-2013-1929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1860" ref_id="CVE-2013-1860"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1848" ref_id="CVE-2013-1848"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1979" ref_id="CVE-2013-1979"/>
        <description>[2.6.39-400.109.1] 

- while removing a non-empty directory, the kernel dumps a message: (rmdir,21743,1):ocfs2_unlink:953 ERROR: status = -39 (Xiaowei.Hu) [Orabug: 16790405] 

- stop mig handler when lockres in progress ,and return -EAGAIN (Xiaowei.Hu) [Orabug: 16876446]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:41.637-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:00.406-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.627-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:128611"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:129047"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:128502"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:129046"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:129468"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.1.el5uek" test_ref="oval:org.mitre.oval:tst:129277"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129380"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129477"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129377"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:128565"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129442"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.1.el6uek" test_ref="oval:org.mitre.oval:tst:129454"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27544" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0277 -- dnsmasq security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dnsmasq</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0277.html" ref_id="ELSA-2013-0277"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3411" ref_id="CVE-2012-3411"/>
        <description>[2.48-13]
- Fix the DHCP RELEASE problem when two or more dnsmasq instances are running (rhbz#887156)

[2.48-12]
- Fixing initscript restart stop functions (rhbz#850944)

[2.48-11]
- Revert previous changes because of many problems with --bind-dynamic option backport.
- Dropping dnsmasq-2.48-add-bind-dynamic-option.patch
- Set SO_BINDTODEVICE socket option when using --bind-interfaces (rhbz#884957)

[2.48-10]
- Fixed dnsmasq-2.48-add-bind-dynamic-option.patch
 - the option --bind-dynamic was not set correctly when used

[2.48-9]
- Added cc flag -fno-strict-aliasing to solve Testsuite regressions

[2.48-8]
- Fix CVE-2012-3411 (rhbz#882251)

[2.48-7]
- Fix lease-change script (rhbz#815819)
- Check tftp-root exists and is accessible at startup (rhbz#824214)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:37.792-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:05:00.198-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.520-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:27:27.780-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:27:27.780-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dnsmasq is earlier than 0:2.48-13.el6" test_ref="oval:org.mitre.oval:tst:130328"/>
          <criterion comment="dnsmasq-utils is earlier than 0:2.48-13.el6" test_ref="oval:org.mitre.oval:tst:129534"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27539" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0687 -- pixman security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0687.html" ref_id="ELSA-2013-0687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1591" ref_id="CVE-2013-1591"/>
        <description>[0.26.2-5]
- Fix bug 914474 (CVE 2013-1591)
- Remove openmp.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:00.291-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:59.595-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:12.197-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:34:38.414-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:34:38.414-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pixman is earlier than 0:0.26.2-5.el6_4" test_ref="oval:org.mitre.oval:tst:129451"/>
          <criterion comment="pixman-devel is earlier than 0:0.26.2-5.el6_4" test_ref="oval:org.mitre.oval:tst:129636"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27536" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0982 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0982.html" ref_id="ELSA-2013-0982"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1682" ref_id="CVE-2013-1682"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1684" ref_id="CVE-2013-1684"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1685" ref_id="CVE-2013-1685"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1686" ref_id="CVE-2013-1686"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1687" ref_id="CVE-2013-1687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1690" ref_id="CVE-2013-1690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1692" ref_id="CVE-2013-1692"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1693" ref_id="CVE-2013-1693"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1694" ref_id="CVE-2013-1694"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1697" ref_id="CVE-2013-1697"/>
        <description>[17.0.7-1.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.7-1]
- Update to 17.0.7 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:16.032-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:58.316-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:11.364-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:22:17.752-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:22:17.752-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129369"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128850"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27532" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0271 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>devhelp</product>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>yelp</product>
          <product>libproxy</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0271.html" ref_id="ELSA-2013-0271"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0780" ref_id="CVE-2013-0780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0783" ref_id="CVE-2013-0783"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0776" ref_id="CVE-2013-0776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0782" ref_id="CVE-2013-0782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0775" ref_id="CVE-2013-0775"/>
        <description>firefox
[17.0.3-1.0.1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.3-1]
- Update to 17.0.3 ESR

[17.0.2-4]
- Added NM preferences

[17.0.2-3]
- Update to 17.0.2 ESR
libproxy
[0.3.0-4]
- Rebuild against newer gecko

xulrunner
[17.0.3-1.0.2]
- Increase release number and rebuild.

[17.0.3-1.0.1]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.3-1]
- Update to 17.0.3 ESR

[17.0.2-5]
- Fixed NetworkManager preferences
- Added fix for NM regression (mozbz#791626)

[17.0.2-2]
- Added fix for rhbz#816234 - NFS fix

[17.0.2-1]
- Update to 17.0.2 ESR

[17.0.1-3]
- Update to 17.0.1 ESR

[17.0-1]
- Update to 17.0 ESR

[17.0-0.6.b5]
- Update to 17 Beta 5
- Updated fix for rhbz#872752 - embeded crash

[17.0-0.5.b4]
- Added fix for rhbz#872752 - embeded crash

[17.0-0.4.b4]
- Update to 17 Beta 4

[17.0-0.3.b3]
- Update to 17 Beta 3
- Updated ppc(64) patch (mozbz#746112)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:52.480-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:57.166-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:10.672-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:30:32.842-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:30:32.842-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="devhelp is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:130366"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130358"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130072"/>
            <criterion comment="yelp is earlier than 0:2.16.0-30.el5_9" test_ref="oval:org.mitre.oval:tst:130124"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:129973"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130278"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.3-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130418"/>
            <criterion comment="libproxy is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:129699"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:129966"/>
            <criterion comment="yelp is earlier than 0:2.28.1-17.el6_3" test_ref="oval:org.mitre.oval:tst:130181"/>
            <criterion comment="libproxy-bin is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130209"/>
            <criterion comment="libproxy-devel is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130273"/>
            <criterion comment="libproxy-gnome is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130114"/>
            <criterion comment="libproxy-kde is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130443"/>
            <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130359"/>
            <criterion comment="libproxy-python is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:129879"/>
            <criterion comment="libproxy-webkit is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:130407"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.0.2.el6_3" test_ref="oval:org.mitre.oval:tst:130125"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27529" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-0519 -- openssh security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0519.html" ref_id="ELSA-2013-0519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5536" ref_id="CVE-2012-5536"/>
        <description>[5.3p1-84.1]
- Add a 'netcat mode' (ssh -W) (#860809)

[5.3p1-83]
- fix the required authentications patch (#869903)

[5.3p1-82]
- check return value of PK11_Authenticate in ssh-add -n (#782912)
- document available methods to RequiredAuthentications[12] (#821641)
- fix ssh-copy-id (#836650)
- fix segmentation fault in ssh client (#836655)
- update pam_ssh_agent_auth to 0.9.3 upstream version
- fix segfault in su when pam_ssh_agent_auth is used and the ssh-agent
  is not running (#834404)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:54.019-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:56.971-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:10.548-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssh is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:130132"/>
          <criterion comment="openssh-askpass is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:130324"/>
          <criterion comment="openssh-clients is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:130379"/>
          <criterion comment="openssh-ldap is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:130299"/>
          <criterion comment="openssh-server is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:130020"/>
          <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9.3-84.1.el6" test_ref="oval:org.mitre.oval:tst:129955"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27528" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1366 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1366.html" ref_id="ELSA-2012-1366"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <description>[2.6.32-279.11.1.el6]
- [net] core: Fix napi_gro_frags vs netpoll path (Amerigo Wang) [857854 845347]
- [netdrv] benet: disable BH in callers of be_process_mcc() (Amerigo Wang) [857854 845347]
- [net] bonding: remove IFF_IN_NETPOLL flag (Amerigo Wang) [857854 845347]
- [mm] fix contig_page_data kABI breakage and related memory corruption (Satoru Moriya) [857012 853007]
- [net] sctp: backport sctp cache ipv6 source after route lookup (Michele Baldessari) [858284 855759]
- [net] sctp: backport support of sctp multi-homing ipv6 source address selection (Michele Baldessari) [858284 855759]
- [net] ipv6: backport RTA_PREFSRC ipv6 source route selection support (Michele Baldessari) [858285 851118]
- [netdrv] sfc: Fix maximum number of TSO segments and minimum TX queue size (Nikolay Aleksandrov) [845556 845557] {CVE-2012-3412}
- [s390] zfcp: No automatic port_rescan on events (Hendrik Brueckner) [856316 855131]
- [fs] xfs: push the AIL from memory reclaim and periodic sync (Dave Chinner) [856686 855139]

[2.6.32-279.10.1.el6]
- [mm] hugetlbfs: close race during teardown of hugetlbfs shared page tables (Rafael Aquini) [857334 856325]
- [mm] hugetlbfs: Correctly detect if page tables have just been shared (Rafael Aquini) [857334 856325]
- [kernel] sched: fix divide by zero at {thread_group,task}_times (Stanislaw Gruszka) [856703 843771]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:28.032-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:56.759-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:10.346-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:45:25.709-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:45:25.709-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:131093"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:131141"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:131068"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:130871"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:131074"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:130403"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:131140"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:130900"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:130963"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27527" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0508 -- sssd security, bug fix and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0508.html" ref_id="ELSA-2013-0508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0220" ref_id="CVE-2013-0220"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0219" ref_id="CVE-2013-0219"/>
        <description>A race condition was found in the way SSSD copied and removed user home
directories. A local attacker who is able to write into the home directory
of a different user who is being removed could use this flaw to perform
symbolic link attacks, possibly allowing them to modify and delete
arbitrary files with the privileges of the root user. (CVE-2013-0219)

Multiple out-of-bounds memory read flaws were found in the way the autofs
and SSH service responders parsed certain SSSD packets. An attacker could
spend a specially-crafted packet that, when processed by the autofs or SSH
service responders, would cause SSSD to crash. This issue only caused a
temporary denial of service, as SSSD was automatically restarted by the
monitor process after the crash. (CVE-2013-0220)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:01.675-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:56.481-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:10.136-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:45:03.028-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:45:03.028-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="sssd is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130130"/>
          <criterion comment="libipa_hbac is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130285"/>
          <criterion comment="libipa_hbac-devel is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130157"/>
          <criterion comment="libipa_hbac-python is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130309"/>
          <criterion comment="libsss_autofs is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130305"/>
          <criterion comment="libsss_idmap is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130057"/>
          <criterion comment="libsss_idmap-devel is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130228"/>
          <criterion comment="libsss_sudo is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130317"/>
          <criterion comment="libsss_sudo-devel is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130099"/>
          <criterion comment="sssd-client is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130315"/>
          <criterion comment="sssd-tools is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:130189"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27525" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0213 -- nss, nss-util, and nspr security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
          <product>nspr-devel</product>
          <product>nss-devel</product>
          <product>nss-pkcs11-devel</product>
          <product>nss-sysinit</product>
          <product>nss-tools</product>
          <product>nss-util-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0213.html" ref_id="ELSA-2013-0213"/>
        <description>nspr
[4.9.2-0.1]
- Retagging to ensure n-v-r is lower than the one for rhel-6.4
- Resolves: rhbz#891661 - [RFE] Rebase nspr to 4.9.2 due to Firefox 17 ESR

[4.9.2-1]
- Resolves: rhbz#891661 - [RFE] Rebase nspr to 4.9.2 due to Firefox 17 ESR

nss
[3.13.6-2.0.1.el6_3]
- Added nss-vendor.patch to change vendor

[3.13.6-2]
- Retagging for rhel-6.3 z-stream
- Update to NSS_3_13_6_RTM
- Resolves: rhbz#891663 - Update to 3.13.5 for mozilla 10.0.6
- Resolves: rhbz#891151 [CVE-2013-0743]

[3.13.6-1]
- Update to NSS_3_13_6_RTM
- Resolves: rhbz#891663 - Update to 3.13.5 for mozilla 10.0.6
- Resolves: rhbz#891151 [CVE-2013-0743]

nss-util
[3.13.6-1]
- Update to NSS_3_13_6_RTM
- Resolves: rhbz#891670 - [RFE] Rebase to NSS-UTIL >= 3.13.6

[3.13.5-1]
- Resolves: rhbz#833763 - Update to 3.13.5 for Mozilla 10.0.6</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:32.478-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:56.361-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:09.987-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:04:53.080-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:04:53.080-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.9.2-0.el6_3.1" test_ref="oval:org.mitre.oval:tst:130439"/>
          <criterion comment="nss is earlier than 0:3.13.6-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130107"/>
          <criterion comment="nss-util is earlier than 0:3.13.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:130552"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.2-0.el6_3.1" test_ref="oval:org.mitre.oval:tst:130488"/>
          <criterion comment="nss-devel is earlier than 0:3.13.6-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130374"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.6-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130078"/>
          <criterion comment="nss-sysinit is earlier than 0:3.13.6-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130414"/>
          <criterion comment="nss-tools is earlier than 0:3.13.6-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130281"/>
          <criterion comment="nss-util-devel is earlier than 0:3.13.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:129857"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27524" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1323 -- qt security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1323.html" ref_id="ELSA-2011-1323"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3193" ref_id="CVE-2011-3193"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3194" ref_id="CVE-2011-3194"/>
        <description>[1:4.6.2-17.1]
- Resolves: #rhbz737812
   fix multiple flaws in Qt
   CVE-2011-3193, CVE-2011-3194</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:20.624-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:56.167-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:09.823-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:15:48.095-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:15:48.095-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qt is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133406"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133396"/>
          <criterion comment="qt-demos is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133532"/>
          <criterion comment="qt-devel is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133257"/>
          <criterion comment="qt-doc is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133338"/>
          <criterion comment="qt-examples is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133443"/>
          <criterion comment="qt-mysql is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133399"/>
          <criterion comment="qt-odbc is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133146"/>
          <criterion comment="qt-postgresql is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133174"/>
          <criterion comment="qt-sqlite is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133264"/>
          <criterion comment="qt-x11 is earlier than 0:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:133181"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27523" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1119 -- 389-ds-base security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1119.html" ref_id="ELSA-2013-1119"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2219" ref_id="CVE-2013-2219"/>
        <description>[1.2.11.15.20]
- Resolves: Bug 984970 - Overflow in nsslapd-disk-monitoring-threshold(part 5 limits not displayed correctly). (ticket 47427)

[1.2.11.15.19]
- Resolves: Bug 984970 - Overflow in nsslapd-disk-monitoring-threshold(part 4). (ticket 47427)
- Patch was not added

[1.2.11.15.19]
- Resolves: Bug 984970 - Overflow in nsslapd-disk-monitoring-threshold(part 4). (ticket 47427)

[1.2.11.15.19]
- Bump version to 1.2.11.15-19
- Resolves: Bug 984970 - Overflow in nsslapd-disk-monitoring-threshold(part 3). (ticket 47427)

[1.2.11.15.18]
- Bump version to 1.2.11.15-18
- Resolves: Bug 984970 - Overflow in nsslapd-disk-monitoring-threshold(part 2). (ticket 47427)
- Resolves: Bug 987850 - Disk Monitoring not checking filesystem with logs (ticket 47741)

[1.2.11.15-17]
- Resolves: Bug 970995 - DS not shutting down when disk monitoring threshold is reached to half. (Ticket 47385)
- Resolves: Bug 984970 - Overflow in nsslapd-disk-monitoring-threshold. (ticket 47427)

[1.2.11.15-16]
- Resolves: Bug 979514 - CVE-2013-2219 ACLs inoperative in some search scenarios. (Ticket 47405)

[1.2.11.15-15]
- Resolves: Bug 970995 - RHDS not shutting down when disk monitoring threshold is reached to half.  (Ticket 47385)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:22.043-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:56.004-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:09.693-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:22:15.118-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:22:15.118-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-20.el6_4" test_ref="oval:org.mitre.oval:tst:129172"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-20.el6_4" test_ref="oval:org.mitre.oval:tst:128921"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-20.el6_4" test_ref="oval:org.mitre.oval:tst:129272"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27522" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1843 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1843.html" ref_id="ELSA-2014-1843"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3611" ref_id="CVE-2014-3611"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3645" ref_id="CVE-2014-3645"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3646" ref_id="CVE-2014-3646"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3185" ref_id="CVE-2014-3185"/>
        <description>[2.6.32-504.1.3]
- Revert: [net] revert 'bridge: Set vlan_features to allow offloads on vlans' (Vlad Yasevich) [1144442 1121991]

[2.6.32-504.1.2]
- [x86] kvm: fix PIT timer race condition (mguzik) [1149592 1149593] {CVE-2014-3611}
- [x86] kvm: vmx: handle invept and invvpid vm exits gracefull (mguzik) [1144826 1144837 1144827 1144838] {CVE-2014-3646 CVE-2014-3645}

[2.6.32-504.1.1]
- [fs] call d_op->d_hash on last component of umount path (Abhijith Das) [1145193 1129712]
- [usb] serial: memory corruption flaw (Jacob Tanenbaum) [1141401 1141402] {CVE-2014-3185}
- [char] ipmi: Clear drvdata when interface is removed (Tony Camuso) [1149578 1135910]
- [char] ipmi: init shadow_ipmi_smi_handlers early in ipmi_si_intf (Tony Camuso) [1149580 1139464]
- [net] ipsec: update MAX_AH_AUTH_LEN to support sha512 (Herbert Xu) [1149083 1140103]
- [net] revert 'bridge: Set vlan_features to allow offloads on vlans' (Vlad Yasevich) [1144442 1121991]
- [netdrv] virtio-net: fix big buffer receiving (Jason Wang) [1148693 1144073]
- [netdrv] tg3: prevent ifup/ifdown during PCI error recovery (Ivan Vecera) [1142570 1117009]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:10:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-17T19:58:46.003-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:46.143-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:12.260-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135587"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135693"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135558"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:134909"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135317"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135378"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135381"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135514"/>
          <criterion comment="perf is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135540"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27521" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0465 -- samba security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0465.html" ref_id="ELSA-2012-0465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1182" ref_id="CVE-2012-1182"/>
        <description>[3.5.10-115]
- Security Release, fixes CVE-2012-1182
- resolves: #804644</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:26.274-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:55.749-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:09.429-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:49:33.844-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:49:33.844-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132187"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132253"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132541"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132589"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132438"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:132367"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132586"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132483"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:131886"/>
            <criterion comment="samba-client is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132416"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132479"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132574"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132525"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132223"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132373"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132555"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132153"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:132264"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27520" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0509 -- rdma security, bug fix and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ibacm</product>
          <product>infinipath-psm</product>
          <product>libibmad</product>
          <product>libibumad</product>
          <product>libibverbs</product>
          <product>libmlx4</product>
          <product>librdmacm</product>
          <product>opensm</product>
          <product>rdma</product>
          <product>ibsim</product>
          <product>ibutils</product>
          <product>infiniband-diags</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0509.html" ref_id="ELSA-2013-0509"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4517" ref_id="CVE-2012-4517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4518" ref_id="CVE-2012-4518"/>
        <description>A denial of service flaw was found in the way ibacm managed reference
counts for multicast connections. An attacker could send specially-crafted
multicast packets that would cause the ibacm daemon to crash.
(CVE-2012-4517)

It was found that the ibacm daemon created some files with world-writable
permissions. A local attacker could use this flaw to overwrite the
contents of the ibacm.log or ibacm.port file, allowing them to mask
certain actions from the log or cause ibacm to run on a non-default port.
(CVE-2012-4518)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:40.152-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:55.405-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:09.131-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:27:05.815-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:27:05.815-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ibsim is earlier than 0:0.5-7.el6" test_ref="oval:org.mitre.oval:tst:130116"/>
          <criterion comment="ibutils is earlier than 0:1.5.7-7.el6" test_ref="oval:org.mitre.oval:tst:130095"/>
          <criterion comment="infiniband-diags is earlier than 0:1.5.12-5.el6" test_ref="oval:org.mitre.oval:tst:129460"/>
          <criterion comment="libibmad is earlier than 0:1.3.9-1.el6" test_ref="oval:org.mitre.oval:tst:130102"/>
          <criterion comment="libibumad is earlier than 0:1.3.8-1.el6" test_ref="oval:org.mitre.oval:tst:129934"/>
          <criterion comment="libibverbs is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:130424"/>
          <criterion comment="libmlx4 is earlier than 0:1.0.4-1.el6" test_ref="oval:org.mitre.oval:tst:130259"/>
          <criterion comment="opensm is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:129913"/>
          <criterion comment="rdma is earlier than 0:3.6-1.0.2.el6" test_ref="oval:org.mitre.oval:tst:130218"/>
          <criterion comment="ibutils-devel is earlier than 0:1.5.7-7.el6" test_ref="oval:org.mitre.oval:tst:129464"/>
          <criterion comment="ibutils-libs is earlier than 0:1.5.7-7.el6" test_ref="oval:org.mitre.oval:tst:130163"/>
          <criterion comment="infiniband-diags-devel is earlier than 0:1.5.12-5.el6" test_ref="oval:org.mitre.oval:tst:130352"/>
          <criterion comment="infiniband-diags-devel-static is earlier than 0:1.5.12-5.el6" test_ref="oval:org.mitre.oval:tst:130082"/>
          <criterion comment="libibmad-devel is earlier than 0:1.3.9-1.el6" test_ref="oval:org.mitre.oval:tst:129911"/>
          <criterion comment="libibmad-static is earlier than 0:1.3.9-1.el6" test_ref="oval:org.mitre.oval:tst:130394"/>
          <criterion comment="libibumad-devel is earlier than 0:1.3.8-1.el6" test_ref="oval:org.mitre.oval:tst:130408"/>
          <criterion comment="libibumad-static is earlier than 0:1.3.8-1.el6" test_ref="oval:org.mitre.oval:tst:129549"/>
          <criterion comment="libibverbs-devel is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:130007"/>
          <criterion comment="libibverbs-devel-static is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:130372"/>
          <criterion comment="libibverbs-utils is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:130368"/>
          <criterion comment="libmlx4-static is earlier than 0:1.0.4-1.el6" test_ref="oval:org.mitre.oval:tst:129604"/>
          <criterion comment="opensm-devel is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:130311"/>
          <criterion comment="opensm-libs is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:129975"/>
          <criterion comment="opensm-static is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:130462"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27519" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0218 -- xorg-x11-drv-qxl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-drv-qxl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0218.html" ref_id="ELSA-2013-0218"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0241" ref_id="CVE-2013-0241"/>
        <description>[0.0.14-14.el6]
- backport of upstream commit 30b4b72cdbdf9f0e92a8d1c4e01779f60f15a741
  support _ASYNC io calls and interrupt handling (busy wait)
  Related: #888364</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:28.627-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:55.231-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:09.008-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:13:01.357-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:13:01.357-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="xorg-x11-drv-qxl is earlier than 0:0.0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:129764"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27518" version="5" class="patch">
      <metadata>
        <title>ELSA-2011-2019 -- Oracle Linux 6 Unbreakable Enterprise kernel security fix update
          (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-2019.html" ref_id="ELSA-2011-2019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1598" ref_id="CVE-2011-1598"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1748" ref_id="CVE-2011-1748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1770" ref_id="CVE-2011-1770"/>
        <description>[2.6.32-100.35.1.el6uek] - [net] dccp: handle invalid feature options length
          {CVE-2011-1770} - [net] can: add missing socket check in can/raw release {CVE-2011-1748} -
          [net] can: Add missing socket check in can/bcm release {CVE-2011-1598}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:29.360-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:54.847-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:08.815-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:36931 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:39.680-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:22.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133600"/>
            <criterion comment="ofa-2.6.32-100.35.1.el5uek is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133341"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:132853"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133705"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133681"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133352"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133775"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.35.1.el5uek" test_ref="oval:org.mitre.oval:tst:133644"/>
            <criterion comment="ofa-2.6.32-100.35.1.el5uekdebug is earlier than 0:1.5.1-4.0.28" test_ref="oval:org.mitre.oval:tst:133664"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133714"/>
            <criterion comment="ofa-2.6.32-100.35.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:133739"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133789"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133268"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133785"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:132920"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133647"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-100.35.1.el6uek" test_ref="oval:org.mitre.oval:tst:133657"/>
            <criterion comment="ofa-2.6.32-100.35.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132851"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27517" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2503 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2503.html" ref_id="ELSA-2013-2503"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4398" ref_id="CVE-2012-4398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4461" ref_id="CVE-2012-4461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4530" ref_id="CVE-2012-4530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0190" ref_id="CVE-2013-0190"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0231" ref_id="CVE-2013-0231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0216" ref_id="CVE-2013-0216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0217" ref_id="CVE-2013-0217"/>
        <description>[2.6.39-300.28.1]

- kmod: make __request_module() killable (Oleg Nesterov) [Orabug: 16286305]

  {CVE-2012-4398}

- kmod: introduce call_modprobe() helper (Oleg Nesterov) [Orabug: 16286305]

  {CVE-2012-4398}

- usermodehelper: implement UMH_KILLABLE (Oleg Nesterov) [Orabug: 16286305]

  {CVE-2012-4398}

- usermodehelper: introduce umh_complete(sub_info) (Oleg Nesterov) [Orabug:

  16286305] {CVE-2012-4398}

- KVM: x86: invalid opcode oops on SET_SREGS with OSXSAVE bit set

  (CVE-2012-4461) (Jerry Snitselaar) [Orabug: 16286290] {CVE-2012-4461}

- exec: do not leave bprm->interp on stack (Kees Cook) [Orabug: 16286267]

  {CVE-2012-4530}

- exec: use -ELOOP for max recursion depth (Kees Cook) [Orabug: 16286267]

  {CVE-2012-4530}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:55.820-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:54.252-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:08.590-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:129523"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:130274"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:130338"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:130392"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:129940"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.28.1.el5uek" test_ref="oval:org.mitre.oval:tst:129839"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130506"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130306"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130325"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130042"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:129926"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.28.1.el6uek" test_ref="oval:org.mitre.oval:tst:130449"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27514" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1114 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1114.html" ref_id="ELSA-2013-1114"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4854" ref_id="CVE-2013-4854"/>
        <description>[32:9.8.2-0.17.rc1.0.2.el6_4.5]
- bump release and build for ULN

[32:9.8.2-0.17.rc1.5]
- fix CVE-2013-4854</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:39.608-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:53.844-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:08.312-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:50:26.048-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:50:26.048-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.5" test_ref="oval:org.mitre.oval:tst:129256"/>
          <criterion comment="bind-chroot is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.5" test_ref="oval:org.mitre.oval:tst:128615"/>
          <criterion comment="bind-devel is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.5" test_ref="oval:org.mitre.oval:tst:129230"/>
          <criterion comment="bind-libs is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.5" test_ref="oval:org.mitre.oval:tst:129135"/>
          <criterion comment="bind-sdb is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.5" test_ref="oval:org.mitre.oval:tst:129144"/>
          <criterion comment="bind-utils is earlier than 0:9.8.2-0.17.rc1.0.2.el6_4.5" test_ref="oval:org.mitre.oval:tst:129288"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27510" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1359 -- xorg-x11-server security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1359.html" ref_id="ELSA-2011-1359"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4818" ref_id="CVE-2010-4818"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4819" ref_id="CVE-2010-4819"/>
        <description>[1.7.7-29.2]
- cve-2011-4818.patch: Multiple input sanitization flaws in GLX and Render</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:11.253-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:53.098-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:07.668-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:46:38.464-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:46:38.464-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133055"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133388"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133256"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133439"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133305"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:132930"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133426"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.0.1.el5_7.5" test_ref="oval:org.mitre.oval:tst:133378"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133203"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133381"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133120"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133020"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133035"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:132723"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133409"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133384"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:133375"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27508" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1156 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1156.html" ref_id="ELSA-2012-1156"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1078" ref_id="CVE-2011-1078"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2383" ref_id="CVE-2012-2383"/>
        <description>[2.6.32-279.5.1.el6]
- [net] 8021q/vlan: filter device events on bonds (Neil Horman) [842429 841983]

[2.6.32-279.4.1.el6]
- [fs] proc: stats: Use arch_idle_time for idle and iowait times if available (Steve Best) [841579 841149]
- [drm] i915: fix integer overflow in i915_gem_execbuffer2() (Jacob Tanenbaum) [824553 824555] {CVE-2012-2383}
- [usb] core: change the memory limits in usbfs URB submission (Don Zickus) [841667 828271]
- [usb] core: unify some error pathways in usbfs (Don Zickus) [841667 828271]
- [netdrv] ixgbe: BIT_APP_UPCHG not set by ixgbe_copy_dcb_cfg() (Andy Gospodarek) [840156 814044]
- [netdrv] ixgbe: driver fix for link flap (Andy Gospodarek) [840156 814044]
- [net] bridge: Fix enforcement of multicast hash_max limit (Thomas Graf) [840023 832575]
- [net] bluetooth: fix sco_conninfo infoleak (Jacob Tanenbaum) [681307 681308] {CVE-2011-1078}
- [wireless] ipw2200: remove references to CFG80211_WEXT config option (John Linville) [841406 839311]
- [netdrv] be2net: enable GRO by default (Ivan Vecera) [838821 837230]
- [virt] kvm/vmx: Fix KVM_SET_SREGS with big real mode segments (Orit Wasserman) [841411 756044]
- [fs] writeback: merge for_kupdate and !for_kupdate cases (Eric Sandeen) [832360 818172]
- [fs] writeback: fix queue_io() ordering (Eric Sandeen) [832360 818172]
- [fs] writeback: don't redirty tail an inode with dirty pages (Eric Sandeen) [832360 818172]

[2.6.32-279.3.1.el6]
- [fs] ext4: properly dirty split extent nodes (David Jeffery) [840052 838640]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:15.498-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:52.671-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:07.210-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:25:25.646-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:25:25.646-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:131458"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:131283"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:131124"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:131378"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:131278"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:130843"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:131020"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:131379"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:131433"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27506" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1732 -- busybox security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>busybox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1732.html" ref_id="ELSA-2013-1732"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1813" ref_id="CVE-2013-1813"/>
        <description>[1:1.15.1-20]

- Resolves: #855832

  'Installation from NFS: That directory could not be mounted from the server'

  by switching NFS mount default from UDP to TCP.

  There was another place (in uclibc this time) which used UDP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:31.161-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:52.504-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:07.060-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="busybox is earlier than 0:1.15.1-20.el6" test_ref="oval:org.mitre.oval:tst:127659"/>
          <criterion comment="busybox-petitboot is earlier than 0:1.15.1-20.el6" test_ref="oval:org.mitre.oval:tst:128250"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27505" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0884 -- libtirpc security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtirpc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0884.html" ref_id="ELSA-2013-0884"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1950" ref_id="CVE-2013-1950"/>
        <description>[0.2.1-6_4]
- Removed a svc_freeargs() call from svc_dg_freeargs() (bz 953735)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:29.443-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:52.310-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:06.924-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:45:32.952-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:45:32.952-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libtirpc is earlier than 0:0.2.1-6.el6_4" test_ref="oval:org.mitre.oval:tst:129290"/>
          <criterion comment="libtirpc-devel is earlier than 0:0.2.1-6.el6_4" test_ref="oval:org.mitre.oval:tst:129262"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27504" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0668 -- boost security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>boost</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0668.html" ref_id="ELSA-2013-0668"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2677" ref_id="CVE-2012-2677"/>
        <description>[1.41.0-15]
- Add in explicit dependences between some boost subpackages

[1.41.0-14]
- Build with -fno-strict-aliasing

[1.41.0-13]
- In Boost.Pool, be careful not to overflow allocated chunk size
  (boost-1.41.0-pool.patch)

[1.41.0-12]
- Add an upstream patch that fixes computation of CRC in zlib streams.
- Resolves: #707624</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:34.941-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:52.029-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:06.665-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:02:23.302-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:02:23.302-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="boost is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:129813"/>
            <criterion comment="boost-devel is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:129814"/>
            <criterion comment="boost-doc is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:129094"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="boost is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129521"/>
            <criterion comment="boost-date-time is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129872"/>
            <criterion comment="boost-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129918"/>
            <criterion comment="boost-doc is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129575"/>
            <criterion comment="boost-filesystem is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129689"/>
            <criterion comment="boost-graph is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129919"/>
            <criterion comment="boost-graph-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129730"/>
            <criterion comment="boost-graph-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129623"/>
            <criterion comment="boost-iostreams is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129830"/>
            <criterion comment="boost-math is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129900"/>
            <criterion comment="boost-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129888"/>
            <criterion comment="boost-mpich2-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129182"/>
            <criterion comment="boost-mpich2-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129227"/>
            <criterion comment="boost-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129064"/>
            <criterion comment="boost-openmpi-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129837"/>
            <criterion comment="boost-openmpi-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129607"/>
            <criterion comment="boost-program-options is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129766"/>
            <criterion comment="boost-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129917"/>
            <criterion comment="boost-regex is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129642"/>
            <criterion comment="boost-serialization is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129908"/>
            <criterion comment="boost-signals is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129577"/>
            <criterion comment="boost-static is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129806"/>
            <criterion comment="boost-system is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129778"/>
            <criterion comment="boost-test is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129875"/>
            <criterion comment="boost-thread is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129309"/>
            <criterion comment="boost-wave is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:129360"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27503" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0869 -- tomcat6 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0869.html" ref_id="ELSA-2013-0869"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1976" ref_id="CVE-2013-1976"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2051" ref_id="CVE-2013-2051"/>
        <description>[0:6.0.24-55]
- Related: rhbz#955976 CVE-2013-1976. Changed log location
- so only root can use it. Touching TOMCAT_LOG is no longer
- required

[0:6.0.24-54]
- Resolves: rhbz#956771 Related: CVE-2012-3439 digest
- authentication broken after errata for cve-2012-3439
- patch for 3439 corrected

[0:6.0.24-53]
- Resolves: rhbz#955976 CVE-2013-1976 improper TOMCAT_LOG
- management in init script</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:40.320-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:51.822-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:06.356-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:04:06.179-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:04:06.179-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:128900"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:128564"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:129509"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:128817"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:129210"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:129174"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:129417"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:129069"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:129320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27502" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2577 -- unbreakable enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>dtrace-modules-3.8.13-16.1.1.el6uek-provider-headers</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2577.html" ref_id="ELSA-2013-2577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4299" ref_id="CVE-2013-4299"/>
        <description>kernel-uek [3.8.13-16.1.1.el6uek] - dm snapshot: fix data corruption (Mikulas
          Patocka) [Orabug: 17617582] {CVE-2013-4299}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:25.396-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:51.646-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:06.269-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35270 - Corrected package names in objects and versions in states." date="2015-02-26T19:47:00.567-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:51:41.452-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:21.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-16.1.1.el6uek is earlier than 0:0.4.0-3.el6" test_ref="oval:org.mitre.oval:tst:128775"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-16.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128673"/>
          <criterion comment="dtrace-modules-3.8.13-16.1.1.el6uek-headers is earlier than 0:0.4.0-3.el6" test_ref="oval:org.mitre.oval:tst:127878"/>
          <criterion comment="dtrace-modules-3.8.13-16.1.1.el6uek-provider-headers is earlier than 0:0.4.0-3.el6" test_ref="oval:org.mitre.oval:tst:128527"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-16.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128787"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-16.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128830"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-16.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128782"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-16.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128695"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-16.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128872"/>
          <criterion comment="kernel-uek-headers is earlier than 0:3.8.13-16.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27501" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1274 -- hplip security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>hplip</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1274.html" ref_id="ELSA-2013-1274"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4325" ref_id="CVE-2013-4325"/>
        <description>[3.12.4-4:.1]
- Applied patch to avoid unix-process authorization subject when using
  polkit as it is racy (CVE-2013-4325).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:27.811-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:51.468-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:06.178-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:31:00.771-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:31:00.771-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="hplip is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:129086"/>
          <criterion comment="hpijs is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:128773"/>
          <criterion comment="hplip-common is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:128542"/>
          <criterion comment="hplip-gui is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:128687"/>
          <criterion comment="hplip-libs is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:129029"/>
          <criterion comment="libsane-hpaio is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:128982"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27500" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0841 -- abrt, libreport, btparser, and python-meh security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>abrt</product>
          <product>btparser</product>
          <product>libreport</product>
          <product>python-meh</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0841.html" ref_id="ELSA-2012-0841"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4088" ref_id="CVE-2011-4088"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1106" ref_id="CVE-2012-1106"/>
        <description>libreport
[2.0.9-5.0.1.el6]
- Add oracle-enterprise.patch
- Remove libreport-plugin-rhtsupport pkg

[2.0.9-5]
- rebuild due to rpmdiff
- Resolves: #823411

[2.0.9-4]
- fixed compatibility with bugzilla 4.2
- Resolves: #823411

[2.0.9-3]
- added notify-only option to mailx rhbz#803618
- Resolves: #803618

[2.0.9-2]
- minor fix in debuginfo downloader
- updated translations
- Related: #759377

[2.0.9-1]
- new upstream release
- fixed typos in man
- fixed handling of anaconda-tb file
- generate valid xml file
- Resolves: #759377, #758366, #746727</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:25.599-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:51.130-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:05.822-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:20:47.115-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:20:47.115-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="abrt is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131673"/>
          <criterion comment="btparser is earlier than 0:0.16-3.el6" test_ref="oval:org.mitre.oval:tst:131639"/>
          <criterion comment="libreport is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131756"/>
          <criterion comment="python-meh is earlier than 0:0.12.1-3.el6" test_ref="oval:org.mitre.oval:tst:131709"/>
          <criterion comment="abrt-addon-ccpp is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131732"/>
          <criterion comment="abrt-addon-kerneloops is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131594"/>
          <criterion comment="abrt-addon-python is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131442"/>
          <criterion comment="abrt-addon-vmcore is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131437"/>
          <criterion comment="abrt-cli is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131341"/>
          <criterion comment="abrt-desktop is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131372"/>
          <criterion comment="abrt-devel is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131785"/>
          <criterion comment="abrt-gui is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:130867"/>
          <criterion comment="abrt-libs is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131726"/>
          <criterion comment="abrt-tui is earlier than 0:2.0.8-6.0.1.el6" test_ref="oval:org.mitre.oval:tst:131603"/>
          <criterion comment="btparser-devel is earlier than 0:0.16-3.el6" test_ref="oval:org.mitre.oval:tst:131593"/>
          <criterion comment="btparser-python is earlier than 0:0.16-3.el6" test_ref="oval:org.mitre.oval:tst:131098"/>
          <criterion comment="libreport-cli is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131615"/>
          <criterion comment="libreport-devel is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131735"/>
          <criterion comment="libreport-gtk is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131708"/>
          <criterion comment="libreport-gtk-devel is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131535"/>
          <criterion comment="libreport-newt is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131548"/>
          <criterion comment="libreport-plugin-bugzilla is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131823"/>
          <criterion comment="libreport-plugin-kerneloops is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131126"/>
          <criterion comment="libreport-plugin-logger is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131530"/>
          <criterion comment="libreport-plugin-mailx is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131219"/>
          <criterion comment="libreport-plugin-reportuploader is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131576"/>
          <criterion comment="libreport-python is earlier than 0:2.0.9-5.0.1.el6" test_ref="oval:org.mitre.oval:tst:131837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27497" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0475 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0475.html" ref_id="ELSA-2011-0475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0070" ref_id="CVE-2011-0070"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0071" ref_id="CVE-2011-0071"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0073" ref_id="CVE-2011-0073"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0074" ref_id="CVE-2011-0074"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0075" ref_id="CVE-2011-0075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0077" ref_id="CVE-2011-0077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0078" ref_id="CVE-2011-0078"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0080" ref_id="CVE-2011-0080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0081" ref_id="CVE-2011-0081"/>
        <description>[3.1.10-1.0.1.el6_0]
- Replaced thunderbird-redhat-default-prefs.js with
  thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[3.1.10-1]
- Update to 3.1.10</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:12.872-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:49.997-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:05.151-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:24:38.291-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:24:38.291-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:3.1.10-1.0.1.el6_0" test_ref="oval:org.mitre.oval:tst:133311"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27494" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2524 -- Unbreakable Enterprise kernel Security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2524.html" ref_id="ELSA-2013-2524"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2094" ref_id="CVE-2013-2094"/>
        <description>[2.6.39-400.24.1]
- perf: Treat attr.config as u64 in perf_swevent_init() (Tommi Rantala) [Orabug: 16808734] {CVE-2013-2094}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:03.896-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:49.409-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:04.651-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129572"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129489"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129339"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:128633"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129569"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.24.1.el5uek" test_ref="oval:org.mitre.oval:tst:129495"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129389"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129554"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129266"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129610"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129471"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.24.1.el6uek" test_ref="oval:org.mitre.oval:tst:129478"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27492" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0062 -- t1lib security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>t1lib</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0062.html" ref_id="ELSA-2012-0062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2642" ref_id="CVE-2010-2642"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0433" ref_id="CVE-2011-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0764" ref_id="CVE-2011-0764"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1552" ref_id="CVE-2011-1552"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1553" ref_id="CVE-2011-1553"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1554" ref_id="CVE-2011-1554"/>
        <description>[5.1.2-6.1]
- Fixed CVE-2010-2642, CVE-2011-0433, CVE-2011-0764, CVE-2011-1552, CVE-2011-1553, CVE-2011-1554
  Resolves: rhbz#772900</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:12.756-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:47.866-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:03.973-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:38:41.489-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:38:41.489-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="t1lib is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:132521"/>
          <criterion comment="t1lib-apps is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:132809"/>
          <criterion comment="t1lib-devel is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:132861"/>
          <criterion comment="t1lib-static is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:132473"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27488" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0839 -- gimp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0839.html" ref_id="ELSA-2011-0839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4540" ref_id="CVE-2010-4540"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4541" ref_id="CVE-2010-4541"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4542" ref_id="CVE-2010-4542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4543" ref_id="CVE-2010-4543"/>
        <description>[2:2.6.9-4.1]
- fix various overflows (#666793, #703403, #703405, #703407, #704512)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:19.953-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:47.143-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:03.458-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:26:08.714-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:26:08.714-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gimp is earlier than 0:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:133676"/>
          <criterion comment="gimp-devel is earlier than 0:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:133623"/>
          <criterion comment="gimp-devel-tools is earlier than 0:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:133585"/>
          <criterion comment="gimp-help-browser is earlier than 0:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:133041"/>
          <criterion comment="gimp-libs is earlier than 0:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:133722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27486" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1534 -- nfs-utils security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1534.html" ref_id="ELSA-2011-1534"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1749" ref_id="CVE-2011-1749"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2500" ref_id="CVE-2011-2500"/>
        <description>[1.2.3-15]
- mout.nfs: Don't roll back to IPv4 whe IPv6 fails (bz 744657)
- rpcdebug: Added pNFS and FSCache debugging (bz 747400)

[1.2.3-14]
- mount.nfs: Backported how upstream handles the SIGXFSZ signal (bz 697981)

[1.2.3-13]
- mount.nfs: Reworked the code that deals with RLIMIT_FSIZE (bz 697981)

[1.2.3-12]
- Removed the stripping of debugging information from rpcdebug (bz 729001)

[1.2.3-11]
- mount.nfs: Fixed problem in mount error verbosity patch (bz 731693)

[1.2.3-10]
- mount.nfs: add error verbosity to invalid versions (bz 731693)

[1.2.3-9]
- umount.nfs: Got IPV6 unmounts working again (bz 732673)
- mountd: return multiple hosts exporting the same directory (bz 726112) 
- mount: Better error message for invalid version (bz 723780)

[1.2.3-8]
- initscripts: just try to mount rpc_pipefs always (bz 692702) 
- Rely on crypto module autoloading in init scripts
- svcgssd: Document '-n' for svcgssd (bz 697359)
- mount.nfs: anticipate RLIMIT_FSIZE (bz 697981)
- exportfs manpage: Ipv6 update (bz 715078)
- mountd: Stop segfault in mtab code (bz 723438)
- exportfs: wilcards in exports can lead to unintended mounts (bz 715391)
- umount: allow spaces in unmount paths (bz 702273)
- specfile: reordered how libgssglue is linked in (bz 720479)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:36.242-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:46.724-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:03.135-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="nfs-utils is earlier than 0:1.2.3-15.el6" test_ref="oval:org.mitre.oval:tst:133040"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27485" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1451 -- java-1.7.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1451.html" ref_id="ELSA-2013-1451"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3829" ref_id="CVE-2013-3829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4002" ref_id="CVE-2013-4002"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5772" ref_id="CVE-2013-5772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5774" ref_id="CVE-2013-5774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5778" ref_id="CVE-2013-5778"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5780" ref_id="CVE-2013-5780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5782" ref_id="CVE-2013-5782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5783" ref_id="CVE-2013-5783"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5784" ref_id="CVE-2013-5784"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5790" ref_id="CVE-2013-5790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5797" ref_id="CVE-2013-5797"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5800" ref_id="CVE-2013-5800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5802" ref_id="CVE-2013-5802"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5803" ref_id="CVE-2013-5803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5804" ref_id="CVE-2013-5804"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5809" ref_id="CVE-2013-5809"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5814" ref_id="CVE-2013-5814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5817" ref_id="CVE-2013-5817"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5820" ref_id="CVE-2013-5820"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5823" ref_id="CVE-2013-5823"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5825" ref_id="CVE-2013-5825"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5829" ref_id="CVE-2013-5829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5830" ref_id="CVE-2013-5830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5838" ref_id="CVE-2013-5838"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5840" ref_id="CVE-2013-5840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5842" ref_id="CVE-2013-5842"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5849" ref_id="CVE-2013-5849"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5850" ref_id="CVE-2013-5850"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5851" ref_id="CVE-2013-5851"/>
        <description>[1.7.0.45-2.4.3.2.0.1.el6]
- Update DISTRO_NAME in specfile</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:56.044-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:44.242-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:02.936-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:08:48.920-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:08:48.920-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.45-2.4.3.2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:127895"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.45-2.4.3.2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128818"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.45-2.4.3.2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128838"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.45-2.4.3.2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128668"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.45-2.4.3.2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27484" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1480 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1480.html" ref_id="ELSA-2013-1480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5590" ref_id="CVE-2013-5590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5595" ref_id="CVE-2013-5595"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5597" ref_id="CVE-2013-5597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5599" ref_id="CVE-2013-5599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5600" ref_id="CVE-2013-5600"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5601" ref_id="CVE-2013-5601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5602" ref_id="CVE-2013-5602"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5604" ref_id="CVE-2013-5604"/>
        <description>[17.0.10-1.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.10-1]
- Update to 17.0.10 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:53.140-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:43.553-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:02.817-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:09:08.563-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:09:08.563-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128697"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27483" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1293 -- squid security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1293.html" ref_id="ELSA-2011-1293"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3205" ref_id="CVE-2011-3205"/>
        <description>[7:3.1.10-1.el6_1.1]
- Resolves: #735447 - CVE-2011-3205 squid: buffer overflow flaw in Squid's Gopher reply parser</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:31">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:08.877-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:43.391-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:02.709-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:51:31.888-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:51:31.888-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="squid is earlier than 0:3.1.10-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:132904"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27482" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1661 -- rdma stack security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>infinipath-psm</product>
          <product>libibverbs</product>
          <product>libmlx4</product>
          <product>librdmacm</product>
          <product>openmpi</product>
          <product>rdma</product>
          <product>ibutils</product>
          <product>mpitests</product>
          <product>mstflint</product>
          <product>perftest</product>
          <product>qperf</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1661.html" ref_id="ELSA-2013-1661"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4516" ref_id="CVE-2012-4516"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2561" ref_id="CVE-2013-2561"/>
        <description>A flaw was found in the way ibutils handled temporary files. A local
attacker could use this flaw to cause arbitrary files to be overwritten as
the root user via a symbolic link attack. (CVE-2013-2561)

It was discovered that librdmacm used a static port to connect to the
ib_acm service. A local attacker able to run a specially crafted ib_acm
service on that port could use this flaw to provide incorrect address
resolution information to librmdacm applications. (CVE-2012-4516)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:20.932-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:42.879-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:02.490-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ibutils is earlier than 0:1.5.7-8.el6" test_ref="oval:org.mitre.oval:tst:128225"/>
          <criterion comment="libibverbs is earlier than 0:1.1.7-1.el6" test_ref="oval:org.mitre.oval:tst:128207"/>
          <criterion comment="libmlx4 is earlier than 0:1.0.5-4.el6.1" test_ref="oval:org.mitre.oval:tst:128273"/>
          <criterion comment="librdmacm is earlier than 0:1.0.17-1.el6" test_ref="oval:org.mitre.oval:tst:127929"/>
          <criterion comment="mpitests is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:128549"/>
          <criterion comment="mstflint is earlier than 0:3.0-0.6.g6961daa.1.el6" test_ref="oval:org.mitre.oval:tst:128445"/>
          <criterion comment="openmpi is earlier than 0:1.5.4-2.0.1.el6" test_ref="oval:org.mitre.oval:tst:128652"/>
          <criterion comment="perftest is earlier than 0:2.0-2.el6" test_ref="oval:org.mitre.oval:tst:128429"/>
          <criterion comment="qperf is earlier than 0:0.4.9-1.0.1.el6" test_ref="oval:org.mitre.oval:tst:128519"/>
          <criterion comment="rdma is earlier than 0:3.10-3.0.1.el6" test_ref="oval:org.mitre.oval:tst:128475"/>
          <criterion comment="ibutils-devel is earlier than 0:1.5.7-8.el6" test_ref="oval:org.mitre.oval:tst:128365"/>
          <criterion comment="ibutils-libs is earlier than 0:1.5.7-8.el6" test_ref="oval:org.mitre.oval:tst:128619"/>
          <criterion comment="libibverbs-devel is earlier than 0:1.1.7-1.el6" test_ref="oval:org.mitre.oval:tst:128328"/>
          <criterion comment="libibverbs-devel-static is earlier than 0:1.1.7-1.el6" test_ref="oval:org.mitre.oval:tst:128299"/>
          <criterion comment="libibverbs-utils is earlier than 0:1.1.7-1.el6" test_ref="oval:org.mitre.oval:tst:128622"/>
          <criterion comment="libmlx4-static is earlier than 0:1.0.5-4.el6.1" test_ref="oval:org.mitre.oval:tst:128376"/>
          <criterion comment="librdmacm-devel is earlier than 0:1.0.17-1.el6" test_ref="oval:org.mitre.oval:tst:128603"/>
          <criterion comment="librdmacm-static is earlier than 0:1.0.17-1.el6" test_ref="oval:org.mitre.oval:tst:128218"/>
          <criterion comment="librdmacm-utils is earlier than 0:1.0.17-1.el6" test_ref="oval:org.mitre.oval:tst:128425"/>
          <criterion comment="mpitests-mvapich is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:128481"/>
          <criterion comment="mpitests-mvapich2 is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:128627"/>
          <criterion comment="mpitests-openmpi is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:128601"/>
          <criterion comment="openmpi-devel is earlier than 0:1.5.4-2.0.1.el6" test_ref="oval:org.mitre.oval:tst:128488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27481" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0821 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0821.html" ref_id="ELSA-2013-0821"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0801" ref_id="CVE-2013-0801"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1670" ref_id="CVE-2013-1670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1674" ref_id="CVE-2013-1674"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1675" ref_id="CVE-2013-1675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1676" ref_id="CVE-2013-1676"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1677" ref_id="CVE-2013-1677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1678" ref_id="CVE-2013-1678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1679" ref_id="CVE-2013-1679"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1680" ref_id="CVE-2013-1680"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1681" ref_id="CVE-2013-1681"/>
        <description>[17.0.6-2.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.6-2]
- Update to 17.0.6 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:48.336-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:41.964-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:02.199-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:12:52.259-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:12:52.259-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129576"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129457"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27480" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0550 -- bind security and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0550.html" ref_id="ELSA-2013-0550"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5689" ref_id="CVE-2012-5689"/>
        <description>A flaw was found in the DNS64 implementation in BIND when using Response
Policy Zones (RPZ). If a remote attacker sent a specially-crafted query to
a named server that is using RPZ rewrite rules, named could exit
unexpectedly with an assertion failure. Note that DNS64 support is not
enabled by default.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:52.888-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:41.761-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:02.108-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:22:51.363-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:22:51.363-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 0:9.8.2-0.17.rc1.0.2.el6.3" test_ref="oval:org.mitre.oval:tst:130279"/>
          <criterion comment="bind-chroot is earlier than 0:9.8.2-0.17.rc1.0.2.el6.3" test_ref="oval:org.mitre.oval:tst:130135"/>
          <criterion comment="bind-devel is earlier than 0:9.8.2-0.17.rc1.0.2.el6.3" test_ref="oval:org.mitre.oval:tst:130194"/>
          <criterion comment="bind-libs is earlier than 0:9.8.2-0.17.rc1.0.2.el6.3" test_ref="oval:org.mitre.oval:tst:129896"/>
          <criterion comment="bind-sdb is earlier than 0:9.8.2-0.17.rc1.0.2.el6.3" test_ref="oval:org.mitre.oval:tst:130245"/>
          <criterion comment="bind-utils is earlier than 0:9.8.2-0.17.rc1.0.2.el6.3" test_ref="oval:org.mitre.oval:tst:130164"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27472" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1426 -- xorg-x11-server security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1426.html" ref_id="ELSA-2013-1426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4396" ref_id="CVE-2013-4396"/>
        <description>[1.13.0-11.1.2]
- CVE-2013-4396: Fix use-after free in ImageText requests (#1014561)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:15.245-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:39.673-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:00.756-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:08:35.517-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:08:35.517-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128704"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128788"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128866"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128337"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128608"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:129015"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128868"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.0.1.el5_10.1" test_ref="oval:org.mitre.oval:tst:128612"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:129021"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128304"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128714"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128951"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128769"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:129004"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128901"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128749"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:128922"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27471" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0216 -- freetype security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0216.html" ref_id="ELSA-2013-0216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5669" ref_id="CVE-2012-5669"/>
        <description>[2.3.11-14.el6_3.1]
- Fix CVE-2012-5669
    (Use correct array size for checking 'glyph_enc')
- Resolves: #903542

[2.3.11-14]
- A little change in configure part
- Related: #723468</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:30.380-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:39.480-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:02:00.587-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:12:24.704-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:12:24.704-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="freetype is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:130534"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:130493"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:130516"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="freetype is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130160"/>
            <criterion comment="freetype-demos is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:129936"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:130545"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27470" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0542 -- Oracle Linux 6.1 kernel security, bug fix and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0542.html" ref_id="ELSA-2011-0542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3881" ref_id="CVE-2010-3881"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4251" ref_id="CVE-2010-4251"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4805" ref_id="CVE-2010-4805"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0999" ref_id="CVE-2011-0999"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1010" ref_id="CVE-2011-1010"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1023" ref_id="CVE-2011-1023"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1082" ref_id="CVE-2011-1082"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1090" ref_id="CVE-2011-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1163" ref_id="CVE-2011-1163"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1170" ref_id="CVE-2011-1170"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1171" ref_id="CVE-2011-1171"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1172" ref_id="CVE-2011-1172"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1494" ref_id="CVE-2011-1494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1495" ref_id="CVE-2011-1495"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1581" ref_id="CVE-2011-1581"/>
        <description>[2.6.32-131.0.15.el6]
- [build] disable Werr for external modules (Aristeu Rozanski) [703504]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:47.873-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:38.253-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:59.646-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:30:53.058-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:30:53.058-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:133853"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:133919"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:133889"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:133885"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:133999"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:134023"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:133227"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:133865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27468" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0748 -- krb5 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0748.html" ref_id="ELSA-2013-0748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1416" ref_id="CVE-2013-1416"/>
        <description>[1.10.3-10.2]
- incorporate upstream patch to fix a NULL pointer dereference while processing
  certain TGS requests (CVE-2013-1416, #950342)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:03.380-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:37.880-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:59.146-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:14:18.060-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:14:18.060-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129700"/>
          <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129393"/>
          <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129443"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129615"/>
          <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129421"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129218"/>
          <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:129668"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27467" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0525 -- pcsc-lite security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pcsc-lite</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0525.html" ref_id="ELSA-2013-0525"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4531" ref_id="CVE-2010-4531"/>
        <description>[1.5.2-11]
- fix overflow issue introduced in 1.5.2-5 and incorrectly corrected in
  1.5.2-6

[1.5.2-10]
- CVE-2010-4531

[1.5.2-9]
- Bump version number so it doesn't get confused with z stream build.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:00.894-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:37.703-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:58.910-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:52:51.342-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:52:51.342-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pcsc-lite is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:130201"/>
          <criterion comment="pcsc-lite-devel is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:130314"/>
          <criterion comment="pcsc-lite-doc is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:130319"/>
          <criterion comment="pcsc-lite-libs is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:130145"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27466" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2534 -- Unbreakable Enterprise kernel Security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2534.html" ref_id="ELSA-2013-2534"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4542" ref_id="CVE-2012-4542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6542" ref_id="CVE-2012-6542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1943" ref_id="CVE-2013-1943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1929" ref_id="CVE-2013-1929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1860" ref_id="CVE-2013-1860"/>
        <description>[2.6.32-400.29.1]
- KVM: add missing void __user COPYING CREDITS Documentation Kbuild MAINTAINERS Makefile README REPORTING-BUGS arch block crypto drivers firmware fs include init ipc kernel lib mm net samples scripts security sound tools uek-rpm usr virt cast to access_ok() call (Heiko Carstens) [Orabug: 16941620] {CVE-2013-1943}
- KVM: Validate userspace_addr of memslot when registered (Takuya Yoshikawa) [Orabug: 16941620] {CVE-2013-1943}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:37.079-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:37.245-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:58.614-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35850 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:00.661-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:20.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129179"/>
            <criterion comment="mlnx_en-2.6.32-400.29.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129445"/>
            <criterion comment="ofa-2.6.32-400.29.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129141"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129287"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:128631"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129107"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:128513"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129472"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.1.el5uek" test_ref="oval:org.mitre.oval:tst:129458"/>
            <criterion comment="mlnx_en-2.6.32-400.29.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129371"/>
            <criterion comment="ofa-2.6.32-400.29.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129500"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:128923"/>
            <criterion comment="mlnx_en-2.6.32-400.29.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129466"/>
            <criterion comment="ofa-2.6.32-400.29.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129122"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129207"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129379"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129192"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129488"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:128553"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.1.el6uek" test_ref="oval:org.mitre.oval:tst:129089"/>
            <criterion comment="mlnx_en-2.6.32-400.29.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128523"/>
            <criterion comment="ofa-2.6.32-400.29.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129113"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27464" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1462 -- mysql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1462.html" ref_id="ELSA-2012-1462"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0540" ref_id="CVE-2012-0540"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1688" ref_id="CVE-2012-1688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1689" ref_id="CVE-2012-1689"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1690" ref_id="CVE-2012-1690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1703" ref_id="CVE-2012-1703"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1734" ref_id="CVE-2012-1734"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2749" ref_id="CVE-2012-2749"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3150" ref_id="CVE-2012-3150"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3158" ref_id="CVE-2012-3158"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3160" ref_id="CVE-2012-3160"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3163" ref_id="CVE-2012-3163"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3166" ref_id="CVE-2012-3166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3167" ref_id="CVE-2012-3167"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3173" ref_id="CVE-2012-3173"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3177" ref_id="CVE-2012-3177"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3180" ref_id="CVE-2012-3180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3197" ref_id="CVE-2012-3197"/>
        <description>[5.1.66-1]
- Update to 5.1.66, for assorted upstream bugfixes including
  CVEs announced in July and October 2012
Resolves: #871813</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:39.934-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:35.678-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:57.479-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:21:39.610-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:21:39.610-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:130606"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:130790"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:130464"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:130624"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:130739"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:130520"/>
          <criterion comment="mysql-server is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:130654"/>
          <criterion comment="mysql-test is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:130638"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27463" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1418 -- libtar security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtar</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1418.html" ref_id="ELSA-2013-1418"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4397" ref_id="CVE-2013-4397"/>
        <description>[1.2.11-17.el6_4.1]
- fix CVE-2013-4397: buffer overflows by expanding a specially-crafted archive</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:14.658-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:35.482-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:57.324-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:59:51.594-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:59:51.594-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libtar is earlier than 0:1.2.11-17.el6_4.1" test_ref="oval:org.mitre.oval:tst:129000"/>
          <criterion comment="libtar-devel is earlier than 0:1.2.11-17.el6_4.1" test_ref="oval:org.mitre.oval:tst:128732"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27462" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0523 -- libpng security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0523.html" ref_id="ELSA-2012-0523"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3048" ref_id="CVE-2011-3048"/>
        <description>[2:1.2.49-1]
- Update to libpng 1.2.49, for minor security issues (CVE-2011-3048)
Resolves: #812714</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:25.518-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:35.302-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:57.209-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:21:11.244-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:21:11.244-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng is earlier than 0:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:131946"/>
            <criterion comment="libpng-devel is earlier than 0:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:132291"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libpng is earlier than 0:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:132101"/>
            <criterion comment="libpng-devel is earlier than 0:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:132191"/>
            <criterion comment="libpng-static is earlier than 0:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:132113"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27461" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3093 -- bash security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3093.html" ref_id="ELSA-2014-3093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6277" ref_id="CVE-2014-6277"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6278" ref_id="CVE-2014-6278"/>
        <description>[4.1.2-29.0.1]
- Fix segfaults from CVE-2014-6277 and CVE-2014-6278 completely. [orabug 19905294]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T11:06:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:34:22.300-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:06.824-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:07.371-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bash is earlier than 0:4.1.2-29.el6.0.1" test_ref="oval:org.mitre.oval:tst:136058"/>
          <criterion comment="bash-doc is earlier than 0:4.1.2-29.el6.0.1" test_ref="oval:org.mitre.oval:tst:135906"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27460" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1540 -- evolution security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cheese</product>
          <product>control-center</product>
          <product>ekiga</product>
          <product>evolution</product>
          <product>evolution-data-server</product>
          <product>evolution-exchange</product>
          <product>evolution-mapi</product>
          <product>gnome-panel</product>
          <product>gnome-python2-desktop</product>
          <product>gtkhtml3</product>
          <product>libgdata</product>
          <product>nautilus-sendto</product>
          <product>openchange</product>
          <product>pidgin</product>
          <product>planner</product>
          <product>totem</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1540.html" ref_id="ELSA-2013-1540"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4166" ref_id="CVE-2013-4166"/>
        <description>Evolution is the integrated collection of email, calendaring, contact
management, communications, and personal information management (PIM) tools
for the GNOME desktop environment.

A flaw was found in the way Evolution selected GnuPG public keys when
encrypting emails. This could result in emails being encrypted with public
keys other than the one belonging to the intended recipient.
(CVE-2013-4166)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:09.677-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:34.852-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:56.809-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cheese is earlier than 0:2.28.1-8.el6" test_ref="oval:org.mitre.oval:tst:128325"/>
          <criterion comment="control-center is earlier than 0:2.28.1-39.el6" test_ref="oval:org.mitre.oval:tst:128584"/>
          <criterion comment="ekiga is earlier than 0:3.2.6-4.el6" test_ref="oval:org.mitre.oval:tst:128618"/>
          <criterion comment="evolution is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:127766"/>
          <criterion comment="evolution-data-server is earlier than 0:2.32.3-18.el6" test_ref="oval:org.mitre.oval:tst:128548"/>
          <criterion comment="evolution-exchange is earlier than 0:2.32.3-16.el6" test_ref="oval:org.mitre.oval:tst:128682"/>
          <criterion comment="evolution-mapi is earlier than 0:0.32.2-12.el6" test_ref="oval:org.mitre.oval:tst:128256"/>
          <criterion comment="gnome-panel is earlier than 0:2.30.2-15.el6" test_ref="oval:org.mitre.oval:tst:128667"/>
          <criterion comment="gnome-python2-desktop is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128496"/>
          <criterion comment="gtkhtml3 is earlier than 0:3.32.2-2.el6" test_ref="oval:org.mitre.oval:tst:128688"/>
          <criterion comment="libgdata is earlier than 0:0.6.4-2.el6" test_ref="oval:org.mitre.oval:tst:128503"/>
          <criterion comment="nautilus-sendto is earlier than 0:2.28.2-4.el6" test_ref="oval:org.mitre.oval:tst:128470"/>
          <criterion comment="openchange is earlier than 0:1.0-6.el6" test_ref="oval:org.mitre.oval:tst:128537"/>
          <criterion comment="pidgin is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128698"/>
          <criterion comment="planner is earlier than 0:0.14.4-10.el6" test_ref="oval:org.mitre.oval:tst:128648"/>
          <criterion comment="totem is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:128686"/>
          <criterion comment="control-center-devel is earlier than 0:2.28.1-39.el6" test_ref="oval:org.mitre.oval:tst:128637"/>
          <criterion comment="control-center-extra is earlier than 0:2.28.1-39.el6" test_ref="oval:org.mitre.oval:tst:127702"/>
          <criterion comment="control-center-filesystem is earlier than 0:2.28.1-39.el6" test_ref="oval:org.mitre.oval:tst:128636"/>
          <criterion comment="evolution-data-server-devel is earlier than 0:2.32.3-18.el6" test_ref="oval:org.mitre.oval:tst:128455"/>
          <criterion comment="evolution-data-server-doc is earlier than 0:2.32.3-18.el6" test_ref="oval:org.mitre.oval:tst:128081"/>
          <criterion comment="evolution-devel is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:128407"/>
          <criterion comment="evolution-devel-docs is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:128510"/>
          <criterion comment="evolution-help is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:127724"/>
          <criterion comment="evolution-mapi-devel is earlier than 0:0.32.2-12.el6" test_ref="oval:org.mitre.oval:tst:128428"/>
          <criterion comment="evolution-perl is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:128501"/>
          <criterion comment="evolution-pst is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:128434"/>
          <criterion comment="evolution-spamassassin is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:127736"/>
          <criterion comment="finch is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128708"/>
          <criterion comment="finch-devel is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128701"/>
          <criterion comment="gnome-panel-devel is earlier than 0:2.30.2-15.el6" test_ref="oval:org.mitre.oval:tst:128579"/>
          <criterion comment="gnome-panel-libs is earlier than 0:2.30.2-15.el6" test_ref="oval:org.mitre.oval:tst:128719"/>
          <criterion comment="gnome-python2-applet is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128660"/>
          <criterion comment="gnome-python2-brasero is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128558"/>
          <criterion comment="gnome-python2-bugbuddy is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128355"/>
          <criterion comment="gnome-python2-evince is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128571"/>
          <criterion comment="gnome-python2-evolution is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128716"/>
          <criterion comment="gnome-python2-gnomedesktop is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128725"/>
          <criterion comment="gnome-python2-gnomekeyring is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128604"/>
          <criterion comment="gnome-python2-gnomeprint is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128474"/>
          <criterion comment="gnome-python2-gtksourceview is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128506"/>
          <criterion comment="gnome-python2-libgtop2 is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128383"/>
          <criterion comment="gnome-python2-libwnck is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:128713"/>
          <criterion comment="gnome-python2-metacity is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:127743"/>
          <criterion comment="gnome-python2-rsvg is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:127761"/>
          <criterion comment="gnome-python2-totem is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:127958"/>
          <criterion comment="gtkhtml3-devel is earlier than 0:3.32.2-2.el6" test_ref="oval:org.mitre.oval:tst:128724"/>
          <criterion comment="libgdata-devel is earlier than 0:0.6.4-2.el6" test_ref="oval:org.mitre.oval:tst:128499"/>
          <criterion comment="libpurple is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128694"/>
          <criterion comment="libpurple-devel is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128641"/>
          <criterion comment="libpurple-perl is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128536"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128745"/>
          <criterion comment="nautilus-sendto-devel is earlier than 0:2.28.2-4.el6" test_ref="oval:org.mitre.oval:tst:128504"/>
          <criterion comment="openchange-client is earlier than 0:1.0-6.el6" test_ref="oval:org.mitre.oval:tst:128301"/>
          <criterion comment="openchange-devel is earlier than 0:1.0-6.el6" test_ref="oval:org.mitre.oval:tst:128448"/>
          <criterion comment="openchange-devel-docs is earlier than 0:1.0-6.el6" test_ref="oval:org.mitre.oval:tst:128253"/>
          <criterion comment="pidgin-devel is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128696"/>
          <criterion comment="pidgin-docs is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128715"/>
          <criterion comment="pidgin-perl is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:128234"/>
          <criterion comment="planner-devel is earlier than 0:0.14.4-10.el6" test_ref="oval:org.mitre.oval:tst:128640"/>
          <criterion comment="planner-eds is earlier than 0:0.14.4-10.el6" test_ref="oval:org.mitre.oval:tst:128538"/>
          <criterion comment="totem-devel is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:128460"/>
          <criterion comment="totem-jamendo is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:128700"/>
          <criterion comment="totem-mozplugin is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:128459"/>
          <criterion comment="totem-nautilus is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:128066"/>
          <criterion comment="totem-upnp is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:128706"/>
          <criterion comment="totem-youtube is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:128547"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27459" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1351 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1351.html" ref_id="ELSA-2012-1351"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1956" ref_id="CVE-2012-1956"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3982" ref_id="CVE-2012-3982"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3986" ref_id="CVE-2012-3986"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3988" ref_id="CVE-2012-3988"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3990" ref_id="CVE-2012-3990"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3991" ref_id="CVE-2012-3991"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3992" ref_id="CVE-2012-3992"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3993" ref_id="CVE-2012-3993"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3994" ref_id="CVE-2012-3994"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3995" ref_id="CVE-2012-3995"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4179" ref_id="CVE-2012-4179"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4180" ref_id="CVE-2012-4180"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4181" ref_id="CVE-2012-4181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4182" ref_id="CVE-2012-4182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4183" ref_id="CVE-2012-4183"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4184" ref_id="CVE-2012-4184"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4185" ref_id="CVE-2012-4185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4186" ref_id="CVE-2012-4186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4187" ref_id="CVE-2012-4187"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4188" ref_id="CVE-2012-4188"/>
        <description>[10.0.8-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[10.0.8-1]
- Update to 10.0.8 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:14.069-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:33.259-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:56.031-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:25:18.016-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:25:18.016-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.0.2.el5_8" test_ref="oval:org.mitre.oval:tst:130685"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131100"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27457" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1051 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1051.html" ref_id="ELSA-2013-1051"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1848" ref_id="CVE-2013-1848"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0914" ref_id="CVE-2013-0914"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3222" ref_id="CVE-2013-3222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3224" ref_id="CVE-2013-3224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6548" ref_id="CVE-2012-6548"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2128" ref_id="CVE-2013-2128"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2634" ref_id="CVE-2013-2634"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2635" ref_id="CVE-2013-2635"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2852" ref_id="CVE-2013-2852"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3225" ref_id="CVE-2013-3225"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3301" ref_id="CVE-2013-3301"/>
        <description>[2.6.32-358.14.1]
- [x86] apic: Add probe() for apic_flat (Prarit Bhargava) [975086 953342]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:32.847-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:32.819-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:55.615-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:29:14.329-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:29:14.329-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:128959"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:128821"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:129104"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:129097"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:128533"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:128984"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:129224"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:129187"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:128352"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27456" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1553 -- qemu-kvm security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1553.html" ref_id="ELSA-2013-1553"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4344" ref_id="CVE-2013-4344"/>
        <description>[qemu-kvm-0.12.1.2-2.415.el6]
- kvm-target-i386-don-t-migrate-steal-time-MSR-on-older-ma.patch [bz#1022821]
- Resolves: bz#1022821
  (live-migration from RHEL6.5 to RHEL6.4.z fails with 'error while loading state for instance 0x0 of device 'cpu'')</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:00.579-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:32.645-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:55.496-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.415.el6" test_ref="oval:org.mitre.oval:tst:127797"/>
          <criterion comment="qemu-guest-agent is earlier than 0:0.12.1.2-2.415.el6" test_ref="oval:org.mitre.oval:tst:128464"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27455" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1100 -- qemu-kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1100.html" ref_id="ELSA-2013-1100"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2231" ref_id="CVE-2013-2231"/>
        <description>[qemu-kvm-0.12.1.2-2.355.el6_4.6]
- kvm-qga-cast-to-int-for-DWORD-type.patch [bz#980758]
- kvm-qga-remove-undefined-behavior-in-ga_install_service.patch [bz#980758]
- kvm-qga-diagnostic-output-should-go-to-stderr.patch [bz#980758]
- kvm-qa_install_service-nest-error-paths-more-idiomatically.patch [bz#980758]
- kvm-qga-escape-cmdline-args-when-registering-win32-service.patch [bz#980758]
- Resolves: bz#980758
  (qemu-kvm: CVE-2013-2231 qemu: qemu-ga win32 service unquoted search path [rhel-6.4.z])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:12.320-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:32.491-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:55.374-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:54:50.208-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:54:50.208-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:129238"/>
          <criterion comment="qemu-guest-agent is earlier than 0:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:129137"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27454" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2519 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2519.html" ref_id="ELSA-2013-2519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1774" ref_id="CVE-2013-1774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1796" ref_id="CVE-2013-1796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1797" ref_id="CVE-2013-1797"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0349" ref_id="CVE-2013-0349"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1767" ref_id="CVE-2013-1767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1798" ref_id="CVE-2013-1798"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1792" ref_id="CVE-2013-1792"/>
        <description>[2.6.39-400.21.2]
- KVM: x86: Convert MSR_KVM_SYSTEM_TIME to use gfn_to_hva_cache functions (CVE-2013-1797) (Andy Honig) [Orabug: 16711660] {CVE-2013-1797}
- Bluetooth: Fix incorrect strncpy() in hidp_setup_hid() (Anderson Lizardo) [Orabug: 16711065] {CVE-2013-0349}
- USB: io_ti: Fix NULL dereference in chase_port() (Wolfgang Frisch) [Orabug: 16425358] {CVE-2013-1774}
- keys: fix race with concurrent install_user_keyrings() (David Howells) [Orabug: 16493354] {CVE-2013-1792}
- KVM: Fix bounds checking in ioapic indirect register reads (CVE-2013-1798) (Andy Honig) [Orabug: 16710951] {CVE-2013-1798}
- KVM: x86: fix for buffer overflow in handling of MSR_KVM_SYSTEM_TIME (CVE-2013-1796) (Andy Honig) [Orabug: 16710806] {CVE-2013-1796}
- tmpfs: fix use-after-free of mempolicy object (Greg Thelen) [Orabug: 16515833] {CVE-2013-1767}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:35.669-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:32.352-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:55.215-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129476"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:128801"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129481"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129672"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129103"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.21.2.el5uek" test_ref="oval:org.mitre.oval:tst:129656"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129298"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129485"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129609"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129171"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129409"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.21.2.el6uek" test_ref="oval:org.mitre.oval:tst:129363"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27453" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0247 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0247.html" ref_id="ELSA-2013-0247"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0424" ref_id="CVE-2013-0424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0425" ref_id="CVE-2013-0425"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0426" ref_id="CVE-2013-0426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0427" ref_id="CVE-2013-0427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0428" ref_id="CVE-2013-0428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0429" ref_id="CVE-2013-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0432" ref_id="CVE-2013-0432"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0433" ref_id="CVE-2013-0433"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0434" ref_id="CVE-2013-0434"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0435" ref_id="CVE-2013-0435"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0440" ref_id="CVE-2013-0440"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0441" ref_id="CVE-2013-0441"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0442" ref_id="CVE-2013-0442"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0443" ref_id="CVE-2013-0443"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0445" ref_id="CVE-2013-0445"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0450" ref_id="CVE-2013-0450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1475" ref_id="CVE-2013-1475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1476" ref_id="CVE-2013-1476"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1478" ref_id="CVE-2013-1478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1480" ref_id="CVE-2013-1480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0431" ref_id="CVE-2013-0431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0444" ref_id="CVE-2013-0444"/>
        <description>[1.7.0.9-2.3.5.3.0.1.el6_3]
- Update DISTRO_NAME in specfile

[1.7.0.9-2.3.5.3.el6_3]
- Sync logging fixes with upstream (icedtea7-forest and jdk7u)

[1.7.0.9-2.3.5.1.el6_3]
- Removed 6664509 backout and added 8005615 to fix the issue

[1.7.0.9-2.3.5.el6_3.1]
- Backed out 6664509 and 7201064.patch which cause regressions

[1.7.0.9-2.3.5.el6_3]
- Bumped to 2.3.5
- Changed BR to java7-devel >= 1:1.7.0 as required by CORBA changes in 2.3.5
- Resolves: rhbz#906707</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:41.812-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:30.589-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:54.309-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:32:38.184-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:32:38.184-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130455"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130086"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130397"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129513"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.5.3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130441"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:129928"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130423"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130417"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130354"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.5.3.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:129835"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27452" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0987 -- sblim-cim-client2 security update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sblim-cim-client2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0987.html" ref_id="ELSA-2012-0987"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2328" ref_id="CVE-2012-2328"/>
        <description>[2.1.3-2]
- Fix possible XML Hash DoS
  Resolves: #803391

[2.1.3]
- Update to sblim-cim-client2-2.1.3

[2.0.9.2-1]
- Initial support</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:10.257-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:30.413-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:54.215-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:33:35.308-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:33:35.308-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="sblim-cim-client2 is earlier than 0:2.1.3-2.el6" test_ref="oval:org.mitre.oval:tst:131612"/>
          <criterion comment="sblim-cim-client2-javadoc is earlier than 0:2.1.3-2.el6" test_ref="oval:org.mitre.oval:tst:131164"/>
          <criterion comment="sblim-cim-client2-manual is earlier than 0:2.1.3-2.el6" test_ref="oval:org.mitre.oval:tst:131749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27450" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0144 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0144.html" ref_id="ELSA-2013-0144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0744" ref_id="CVE-2013-0744"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0746" ref_id="CVE-2013-0746"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0748" ref_id="CVE-2013-0748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0750" ref_id="CVE-2013-0750"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0753" ref_id="CVE-2013-0753"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0754" ref_id="CVE-2013-0754"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0758" ref_id="CVE-2013-0758"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0759" ref_id="CVE-2013-0759"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0762" ref_id="CVE-2013-0762"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0766" ref_id="CVE-2013-0766"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0767" ref_id="CVE-2013-0767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0769" ref_id="CVE-2013-0769"/>
        <description>firefox
[10.0.12-1.0.1.el6_3]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[10.0.12-1]
- Update to 10.0.12 ESR

xulrunner
[10.0.12-1.0.1.el6_3]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.12-1]
- Update to 10.0.12 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:23.792-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:29.386-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:53.709-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:47:49.489-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:47:49.489-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.12-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130718"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130079"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130496"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.12-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130727"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130303"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130333"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27449" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0165 -- java-1.7.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0165.html" ref_id="ELSA-2013-0165"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3174" ref_id="CVE-2012-3174"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0422" ref_id="CVE-2013-0422"/>
        <description>[1.7.0.9-2.3.4.1.0.1.el6_3]
- Update DISTRO_NAME in specfile

[1.7.0.9-2.3.4.1.el6]
- Rewerted to IcedTea 2.3.4
  - rewerted patch105: java-1.7.0-openjdk-disable-system-lcms.patch
  - removed jxmd and idlj to alternatives
  - make NOT executed with   DISABLE_INTREE_EC=true and UNLIMITED_CRYPTO=true
  - re-applied patch302 and restored systemtap.patch
  - buildver set to 9
  - icedtea_version set to 2.3.4
  - unapplied patch112 java-1.7.openjdk-doNotUseDisabledEcc.patch
  - restored tmp-patches source tarball
  - removed /lib/security/US_export_policy.jar and lib/security/local_policy.jar
  - java-1.7.0-openjdk-java-access-bridge-security.patch's path moved from
    java.security-linux back to java.security
- Resolves: rhbz#895033

[1.7.0.11-2.4.0.1.el6]
- Rewritten patch105: java-1.7.0-openjdk-disable-system-lcms.patch
- Added jxmd and idlj to alternatives
- make executed with   DISABLE_INTREE_EC=true and UNLIMITED_CRYPTO=true
- Unapplied patch302 and deleted systemtap.patch
- buildver increased to 11
- icedtea_version set to 2.4.0
- Added and applied patch112 java-1.7.openjdk-doNotUseDisabledEcc.patch
- removed tmp-patches source tarball
- Added /lib/security/US_export_policy.jar and lib/security/local_policy.jar
- Resolves: rhbz#895033</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:48.968-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:29.083-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:53.541-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:29:12.907-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:29:12.907-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130612"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130660"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130470"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130588"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.4.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130564"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130645"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:129873"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:129941"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130650"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.9-2.3.4.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130158"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27448" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0710 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0710.html" ref_id="ELSA-2012-0710"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3101" ref_id="CVE-2011-3101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1937" ref_id="CVE-2012-1937"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1938" ref_id="CVE-2012-1938"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1939" ref_id="CVE-2012-1939"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1940" ref_id="CVE-2012-1940"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1941" ref_id="CVE-2012-1941"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1944" ref_id="CVE-2012-1944"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1945" ref_id="CVE-2012-1945"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1946" ref_id="CVE-2012-1946"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1947" ref_id="CVE-2012-1947"/>
        <description>firefox:

[10.0.5-1.0.1.el6_2]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.5-1]
- Update to 10.0.5 ESR

xulrunner:

[10.0.5-1.0.1.el6_2]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.5-1]
- Update to 10.0.5 ESR

[10.0.4-2]
- Added patch for mozbz#703633</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:02.452-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:28.031-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:53.123-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:28:16.533-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:28:16.533-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.5-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131452"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131977"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131962"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.5-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131694"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131343"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:131935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27447" version="3" class="patch">
      <metadata>
        <title>ELSA-2011-1532 -- kexec-tools security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kexec-tools</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1532.html" ref_id="ELSA-2011-1532"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3588" ref_id="CVE-2011-3588"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3589" ref_id="CVE-2011-3589"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3590" ref_id="CVE-2011-3590"/>
        <description>Kdump used the SSH (Secure Shell) "StrictHostKeyChecking=no" option when
dumping to SSH targets, causing the target kdump server's SSH host key not
to be checked. This could make it easier for a man-in-the-middle attacker
on the local network to impersonate the kdump SSH target server and
possibly gain access to sensitive information in the vmcore dumps.
(CVE-2011-3588)

mkdumprd created initrd files with world-readable permissions. A local user
could possibly use this flaw to gain access to sensitive information, such
as the private SSH key used to authenticate to a remote server when kdump
was configured to dump to an SSH target. (CVE-2011-3589)

mkdumprd included unneeded sensitive files (such as all files from the
"/root/.ssh/" directory and the host's private SSH keys) in the resulting
initrd. This could lead to an information leak when initrd files were
previously created with world-readable permissions. Note: With this update,
only the SSH client configuration, known hosts files, and the SSH key
configured via the newly introduced sshkey option in "/etc/kdump.conf" are
included in the initrd. The default is the key generated when running the
"service kdump propagate" command, "/root/.ssh/kdump_id_rsa".
(CVE-2011-3590)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:24">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:06.141-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:27.610-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:52.791-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="kexec-tools is earlier than 0:2.0.0-209.0.1.el6" test_ref="oval:org.mitre.oval:tst:133019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27445" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-1002 -- mod_auth_mysql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mod_auth_mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-1002.html" ref_id="ELSA-2010-1002"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2384" ref_id="CVE-2008-2384"/>
        <description>[1:3.0.0-11.1]
- add security fix for CVE-2008-2384 (#663617)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:49.443-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:27.371-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:52.657-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:28:09.386-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:28:09.386-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="mod_auth_mysql is earlier than 0:3.0.0-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:134385"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27444" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0504 -- dhcp security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0504.html" ref_id="ELSA-2013-0504"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3955" ref_id="CVE-2012-3955"/>
        <description>[12:4.1.1-34.P1.0.1.el6]
- Added oracle-errwarn-message.patch

[12:4.1.1-34.P1]
- Reducing the expiration time for an IPv6 lease may cause the server to crash
  (CVE-2012-3955, #858130)

[12:4.1.1-33.P1]
- Use getifaddrs() for interface discovery code on Linux (#803540)
- dhclient-script: do not backup&amp;restore /etc/resolv.conf (#824622)

[12:4.1.1-32.P1]
- An error in the handling of malformed client identifiers can
  cause a denial-of-service condition in affected servers. (CVE-2012-3571, #843122)
- Memory Leaks Found In ISC DHCP (CVE-2012-3954, #843122)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:33.514-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:27.148-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:52.570-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:42:28.476-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:42:28.476-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dhcp is earlier than 0:4.1.1-34.P1.0.1.el6" test_ref="oval:org.mitre.oval:tst:130052"/>
          <criterion comment="dhclient is earlier than 0:4.1.1-34.P1.0.1.el6" test_ref="oval:org.mitre.oval:tst:130422"/>
          <criterion comment="dhcp-common is earlier than 0:4.1.1-34.P1.0.1.el6" test_ref="oval:org.mitre.oval:tst:130416"/>
          <criterion comment="dhcp-devel is earlier than 0:4.1.1-34.P1.0.1.el6" test_ref="oval:org.mitre.oval:tst:130433"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27442" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1615 -- php security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1615.html" ref_id="ELSA-2013-1615"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7243" ref_id="CVE-2006-7243"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1643" ref_id="CVE-2013-1643"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4248" ref_id="CVE-2013-4248"/>
        <description>[5.3.3-26]

- add security fix for CVE-2013-4248



[5.3.3-25]

- rename patch to math CVE-2010-3709 name

- add security fixes for CVE-2006-7243, CVE-2013-1643



[5.3.3-24]

- fix buffer overflow in _pdo_pgsql_error (#969110)

- fix double free when destroy_zend_class fails (#910466)

- fix segfault in error_handler with

  allow_call_time_pass_reference = Off (#892158)

- fix copy doesn't report failure on partial copy (#947428)

- add rpm macros for packagers: %php_inidir,

  %php_incldir and %__php (#953814)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:06.773-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:26.544-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:52.349-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128554"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128457"/>
          <criterion comment="php-cli is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128307"/>
          <criterion comment="php-common is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128573"/>
          <criterion comment="php-dba is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128163"/>
          <criterion comment="php-devel is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128653"/>
          <criterion comment="php-embedded is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128625"/>
          <criterion comment="php-enchant is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128463"/>
          <criterion comment="php-fpm is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128498"/>
          <criterion comment="php-gd is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:127679"/>
          <criterion comment="php-imap is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128391"/>
          <criterion comment="php-intl is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:127947"/>
          <criterion comment="php-ldap is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128566"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128614"/>
          <criterion comment="php-mysql is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128645"/>
          <criterion comment="php-odbc is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128388"/>
          <criterion comment="php-pdo is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:127692"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128583"/>
          <criterion comment="php-process is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128377"/>
          <criterion comment="php-pspell is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128572"/>
          <criterion comment="php-recode is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128593"/>
          <criterion comment="php-snmp is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128562"/>
          <criterion comment="php-soap is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128605"/>
          <criterion comment="php-tidy is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128439"/>
          <criterion comment="php-xml is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128658"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:127838"/>
          <criterion comment="php-zts is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:128532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27441" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1049 -- php security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1049.html" ref_id="ELSA-2013-1049"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4113" ref_id="CVE-2013-4113"/>
        <description>[5.3.3-23]
- add security fix for CVE-2013-4113</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:13.399-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:26.122-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:52.062-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:12:51.760-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:12:51.760-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128599"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128899"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129352"/>
            <criterion comment="php-common is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128952"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128815"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129330"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129321"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129325"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129334"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129112"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129331"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:128736"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129142"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129295"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129305"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129235"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129285"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129343"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:129216"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128920"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129193"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129071"/>
            <criterion comment="php-common is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129250"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129247"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128877"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129081"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128778"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129201"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128889"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129184"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129284"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128709"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129304"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129241"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129139"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128546"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129293"/>
            <criterion comment="php-process is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129314"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129049"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128531"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129009"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129143"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129095"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129126"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:128943"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:129282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27440" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1674 -- dracut security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dracut</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1674.html" ref_id="ELSA-2013-1674"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4453" ref_id="CVE-2012-4453"/>
        <description>[004-336.0.1]

- do not strip modules with signatures. [orabug 17458249] (Jerry Snitselaar)

- scsi_wait module removed in 3.8. Mute errors. [orabug 16977193] (Maxim Uvarov)

  find firmware in /lib/modules/firmware/2.6.32-400.1.1.el5uek first

  and /lib/modules/firmware second (&lt;maxim.uvarov@oracle.com)

  Resolves: Orabug: 13351090

- Fix btrfs discovery [orabug 13388545]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:03.168-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:25.885-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:51.877-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dracut is earlier than 0:004-336.0.1.el6" test_ref="oval:org.mitre.oval:tst:128200"/>
          <criterion comment="dracut-caps is earlier than 0:004-336.0.1.el6" test_ref="oval:org.mitre.oval:tst:127700"/>
          <criterion comment="dracut-fips is earlier than 0:004-336.0.1.el6" test_ref="oval:org.mitre.oval:tst:128458"/>
          <criterion comment="dracut-fips-aesni is earlier than 0:004-336.0.1.el6" test_ref="oval:org.mitre.oval:tst:128656"/>
          <criterion comment="dracut-generic is earlier than 0:004-336.0.1.el6" test_ref="oval:org.mitre.oval:tst:128168"/>
          <criterion comment="dracut-kernel is earlier than 0:004-336.0.1.el6" test_ref="oval:org.mitre.oval:tst:128206"/>
          <criterion comment="dracut-network is earlier than 0:004-336.0.1.el6" test_ref="oval:org.mitre.oval:tst:128576"/>
          <criterion comment="dracut-tools is earlier than 0:004-336.0.1.el6" test_ref="oval:org.mitre.oval:tst:128574"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27439" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2021 -- Unbreakable Enterprise kernel security and bugfix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2021.html" ref_id="ELSA-2012-2021"/>
        <description>[2.6.39-100.10.1.el6uek]
- thp: avoid atomic64_read in pmd_read_atomic for 32bit PAE (Andrea Arcangeli)
  [Orabug: 14217003]

[2.6.39-100.9.1.el6uek]
- mm: pmd_read_atomic: fix 32bit PAE pmd walk vs pmd_populate SMP race
  condition (Andrea Arcangeli) [Bugdb: 13966] {CVE-2012-2373}
- mm: thp: fix pmd_bad() triggering in code paths holding mmap_sem read mode
  (Andrea Arcangeli)  {CVE-2012-1179}
- KVM: Fix buffer overflow in kvm_set_irq() (Avi Kivity) [Bugdb: 13966]
  {CVE-2012-2137}
- net: sock: validate data_len before allocating skb in sock_alloc_send_pskb()
  (Jason Wang) [Bugdb: 13966] {CVE-2012-2136}
- KVM: lock slots_lock around device assignment (Alex Williamson) [Bugdb:
  13966] {CVE-2012-2121}
- KVM: unmap pages from the iommu when slots are removed (Alex Williamson)
  [Bugdb: 13966] {CVE-2012-2121}
- KVM: introduce kvm_for_each_memslot macro (Xiao Guangrong) [Bugdb: 13966]
- fcaps: clear the same personality flags as suid when fcaps are used (Eric
  Paris) [Bugdb: 13966] {CVE-2012-2123}

[2.6.39-100.8.1.el6uek]
- net: ipv4: relax AF_INET check in bind() (Eric Dumazet) [Orabug: 14054411]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:17.192-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:25.705-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:51.732-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131923"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131904"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131864"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131911"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131213"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.10.1.el5uek" test_ref="oval:org.mitre.oval:tst:131523"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131449"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131866"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131846"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131011"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131624"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.10.1.el6uek" test_ref="oval:org.mitre.oval:tst:131532"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27434" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0533 -- samba and samba3x security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0533.html" ref_id="ELSA-2012-0533"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2111" ref_id="CVE-2012-2111"/>
        <description>[3.5.10-116]
- Security Release, fixes CVE-2012-2111
- resolves: #815688</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:28.696-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:24.488-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:50.911-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:23:20.888-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:23:20.888-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba3x is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132323"/>
            <criterion comment="samba3x-client is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132094"/>
            <criterion comment="samba3x-common is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132339"/>
            <criterion comment="samba3x-doc is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:131989"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132309"/>
            <criterion comment="samba3x-swat is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:132417"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:131873"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:131926"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132195"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132375"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132181"/>
            <criterion comment="samba-client is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132407"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:131503"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132462"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132289"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132039"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132263"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132313"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132176"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:132411"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27433" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2537 -- unbreakable enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2537.html" ref_id="ELSA-2013-2537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0914" ref_id="CVE-2013-0914"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3222" ref_id="CVE-2013-3222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3224" ref_id="CVE-2013-3224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6548" ref_id="CVE-2012-6548"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2634" ref_id="CVE-2013-2634"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2852" ref_id="CVE-2013-2852"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3225" ref_id="CVE-2013-3225"/>
        <description>kernel-uek
[2.6.32-400.29.2uek]
- Bluetooth: RFCOMM - Fix missing msg_namelen update in rfcomm_sock_recvmsg() (Mathias Krause) [Orabug: 17173824] {CVE-2013-3225}
- Bluetooth: fix possible info leak in bt_sock_recvmsg() (Mathias Krause) [Orabug: 17173824] {CVE-2013-3224}
- atm: update msg_namelen in vcc_recvmsg() (Mathias Krause) [Orabug: 17173824] {CVE-2013-3222}
- dcbnl: fix various netlink info leaks (Mathias Krause) [Orabug: 17173824] {CVE-2013-2634}
- udf: avoid info leak on export (Mathias Krause) [Orabug: 17173824] {CVE-2012-6548}
- b43: stop format string leaking into error msgs (Kees Cook) [Orabug: 17173824] {CVE-2013-2852}
- signal: always clear sa_restorer on execve (Kees Cook) [Orabug: 17173824] {CVE-2013-0914}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:21.500-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:23.995-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:50.647-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35528 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:00.217-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:20.441-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:128820"/>
            <criterion comment="mlnx_en-2.6.32-400.29.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129132"/>
            <criterion comment="ofa-2.6.32-400.29.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129261"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129203"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129121"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129165"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129237"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129136"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:129269"/>
            <criterion comment="mlnx_en-2.6.32-400.29.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129278"/>
            <criterion comment="ofa-2.6.32-400.29.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129168"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:128495"/>
            <criterion comment="mlnx_en-2.6.32-400.29.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128672"/>
            <criterion comment="ofa-2.6.32-400.29.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129054"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:128933"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:129195"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:128934"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:129274"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:128848"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:129116"/>
            <criterion comment="mlnx_en-2.6.32-400.29.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128793"/>
            <criterion comment="ofa-2.6.32-400.29.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129255"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27432" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0413 -- glibc security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0413.html" ref_id="ELSA-2011-0413"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0536" ref_id="CVE-2011-0536"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1071" ref_id="CVE-2011-1071"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1095" ref_id="CVE-2011-1095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1658" ref_id="CVE-2011-1658"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1659" ref_id="CVE-2011-1659"/>
        <description>[2.12-1.7.el6_0.5]
- Avoid too much stack use in fnmatch (#681054, CVE-2011-1071)
- Properly quote output of locale (#625893, CVE-2011-1095)
- Don't leave empty element in rpath when skipping the first element,
  ignore rpath elements containing non-isolated use of  when
  privileged (#667974, CVE-2011-0536)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:53">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:11.396-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:23.508-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:50.331-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:11:06.457-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:11:06.457-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:134005"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:133941"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:133978"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:134001"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:133188"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:134156"/>
          <criterion comment="nscd is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:133871"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27431" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2584 -- Unbreakable Enterprise Kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2584.html" ref_id="ELSA-2013-2584"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6545" ref_id="CVE-2012-6545"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3231" ref_id="CVE-2013-3231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343" ref_id="CVE-2013-0343"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4345" ref_id="CVE-2013-4345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1928" ref_id="CVE-2013-1928"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2888" ref_id="CVE-2013-2888"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2889" ref_id="CVE-2013-2889"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2892" ref_id="CVE-2013-2892"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4387" ref_id="CVE-2013-4387"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4592" ref_id="CVE-2013-4592"/>
        <description>[2.6.39-400.211.2]
- fs/compat_ioctl.c: VIDEO_SET_SPU_PALETTE missing error check (Kees Cook) [Orabug: 17842208] {CVE-2013-1928}
- Bluetooth: RFCOMM - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17842129] {CVE-2012-6545}
- Bluetooth: RFCOMM - Fix info leak in ioctl(RFCOMMGETDEVLIST) (Mathias Krause) [Orabug: 17842105] {CVE-2012-6545}
- llc: Fix missing msg_namelen update in llc_ui_recvmsg() (Mathias Krause) [Orabug: 17842095] {CVE-2013-3231}
- HID: pantherlord: validate output report details (Kees Cook) [Orabug: 17842084] {CVE-2013-2892}
- HID: zeroplus: validate output report details (Kees Cook) [Orabug: 17842081] {CVE-2013-2889}
- HID: provide a helper for validating hid reports (Kees Cook) [Orabug: 17842081] {CVE-2013-2889}
- KVM: Fix iommu map/unmap to handle memory slot moves (Jerry Snitselaar) [Orabug: 17842075] {CVE-2013-4592}
- ansi_cprng: Fix off by one error in non-block size request (Jerry Snitselaar) [Orabug: 17842072] {CVE-2013-4345}
- HID: validate HID report id size (Kees Cook) [Orabug: 17842063] {CVE-2013-2888}
- ipv6: remove max_addresses check from ipv6_create_tempaddr (Hannes Frederic Sowa) [Orabug: 17842056] {CVE-2013-0343}
- ipv6: udp packets following an UFO enqueued packet need also be handled by UFO (Hannes Frederic Sowa) [Orabug: 17842050] {CVE-2013-4387}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:53.256-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:23.336-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:50.111-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128420"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128175"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128485"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128397"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:127806"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.211.2.el5uek" test_ref="oval:org.mitre.oval:tst:128468"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128453"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128170"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128437"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128173"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:127888"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.211.2.el6uek" test_ref="oval:org.mitre.oval:tst:128441"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27430" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1590 -- libtiff security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1590.html" ref_id="ELSA-2012-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3401" ref_id="CVE-2012-3401"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4447" ref_id="CVE-2012-4447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4564" ref_id="CVE-2012-4564"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5581" ref_id="CVE-2012-5581"/>
        <description>[3.9.4-9]
- Still more fixes to make test case for CVE-2012-5581 work on all platforms
Resolves: #885310

[3.9.4-8]
- Fix incomplete patch for CVE-2012-3401
- Add libtiff-tiffinfo-exif.patch so that our test case for CVE-2012-5581 works
  with pre-4.0.2 libtiff
Resolves: #885310

[3.9.4-7]
- Add fixes for CVE-2012-3401, CVE-2012-4447, CVE-2012-4564, CVE-2012-5581
Resolves: #885310</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:38.010-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:22.915-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:49.848-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:18:11.334-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:18:11.334-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:130813"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:130436"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:130380"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:129947"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:130431"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27429" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1105 -- libpng security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1105.html" ref_id="ELSA-2011-1105"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2501" ref_id="CVE-2011-2501"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2690" ref_id="CVE-2011-2690"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2692" ref_id="CVE-2011-2692"/>
        <description>[2:1.2.46-1]
- Update to libpng 1.2.46, includes fixes for CVE-2011-2501, CVE-2011-2690,
  CVE-2011-2691, CVE-2011-2692
Resolves: #721305</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:33.520-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:22.576-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:49.683-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:28:26.555-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:28:26.555-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libpng is earlier than 0:1.2.46-1.el6_1" test_ref="oval:org.mitre.oval:tst:132738"/>
          <criterion comment="libpng-devel is earlier than 0:1.2.46-1.el6_1" test_ref="oval:org.mitre.oval:tst:133636"/>
          <criterion comment="libpng-static is earlier than 0:1.2.46-1.el6_1" test_ref="oval:org.mitre.oval:tst:133334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27428" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1459 -- gnupg2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnupg2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1459.html" ref_id="ELSA-2013-1459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6085" ref_id="CVE-2012-6085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4351" ref_id="CVE-2013-4351"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4402" ref_id="CVE-2013-4402"/>
        <description>[2.0.14-6]
- fix CVE-2013-4351 gpg treats no-usage-permitted keys as all-usages-permitted

[2.0.14-5]
- fix CVE-2012-6085 GnuPG: read_block() corrupt key input validation
- fix CVE-2013-4402 GnuPG: infinite recursion in the compressed packet parser</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:01.310-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:22.195-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:49.425-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:38:42.583-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:38:42.583-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="gnupg2 is earlier than 0:2.0.10-6.el5_10" test_ref="oval:org.mitre.oval:tst:128570"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gnupg2 is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:128235"/>
            <criterion comment="gnupg2-smime is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:128730"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27427" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1652 -- coreutils security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>coreutils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1652.html" ref_id="ELSA-2013-1652"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0221" ref_id="CVE-2013-0221"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0222" ref_id="CVE-2013-0222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0223" ref_id="CVE-2013-0223"/>
        <description>[8.4-31.0.1]

- clean up empty file if cp is failed [Orabug 15973168]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:35.505-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:21.830-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:49.265-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="coreutils is earlier than 0:8.4-31.0.1.el6" test_ref="oval:org.mitre.oval:tst:128522"/>
          <criterion comment="coreutils-libs is earlier than 0:8.4-31.0.1.el6" test_ref="oval:org.mitre.oval:tst:128022"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27426" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1409 -- xinetd security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1409.html" ref_id="ELSA-2013-1409"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4342" ref_id="CVE-2013-4342"/>
        <description>[2:2.3.14-39]
- Honor user and group directives
- Resolves: CVE-2013-4342</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:15.555-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:21.661-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:49.177-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:14:50.037-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:14:50.037-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="xinetd is earlier than 0:2.3.14-20.el5_10" test_ref="oval:org.mitre.oval:tst:129023"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="xinetd is earlier than 0:2.3.14-39.el6_4" test_ref="oval:org.mitre.oval:tst:128919"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27422" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0523 -- ccid security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ccid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0523.html" ref_id="ELSA-2013-0523"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4530" ref_id="CVE-2010-4530"/>
        <description>[1.3.9.6]
- CVE-2010-4530 patch

[1.3.9-5]
- Fix dist tag

[1.3.9-4]
- Check multiple voltages, even if we started with 5V.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:40.593-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:20.363-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:48.336-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:53:09.767-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:53:09.767-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="ccid is earlier than 0:1.3.9-6.el6" test_ref="oval:org.mitre.oval:tst:130188"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27421" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0421 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0421.html" ref_id="ELSA-2011-0421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3296" ref_id="CVE-2010-3296"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4346" ref_id="CVE-2010-4346"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4526" ref_id="CVE-2010-4526"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4648" ref_id="CVE-2010-4648"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4655" ref_id="CVE-2010-4655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4656" ref_id="CVE-2010-4656"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0521" ref_id="CVE-2011-0521"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0695" ref_id="CVE-2011-0695"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0710" ref_id="CVE-2011-0710"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0716" ref_id="CVE-2011-0716"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1478" ref_id="CVE-2011-1478"/>
        <description>[2.6.32-71.24.1.el6]
- [fs] Revert '[fs] inotify: stop kernel memory leak on file creation failure' (Eric Paris) [656831 656832] {CVE-2010-4250}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:46.828-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:19.339-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:47.833-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:57:53.356-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:57:53.356-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:134142"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:133881"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:134056"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:133929"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:133285"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:134114"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:133591"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:133537"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27420" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1805 -- samba4 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1805.html" ref_id="ELSA-2013-1805"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408" ref_id="CVE-2013-4408"/>
        <description>[4.0.0-60.rc4]
- resolves: #1018039 - Fix CVE-2013-4408.

[4.0.0-59.rc4]
- Fix usage of client min/max protocol options in winbindd
- related: #949993</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:33.175-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:19.176-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:47.703-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:51:42.396-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:51:42.396-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba4 is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128259"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128184"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128300"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:127430"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128193"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128224"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128158"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128419"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128258"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128363"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128284"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128247"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128094"/>
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:128318"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27419" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0468 -- libtiff security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0468.html" ref_id="ELSA-2012-0468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1173" ref_id="CVE-2012-1173"/>
        <description>[3.9.4-5]
- Add fix for CVE-2012-1173
Resolves: #CVE-2012-1173</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:27.812-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:18.928-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:47.581-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:02:17.880-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:02:17.880-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:132099"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:132492"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:132294"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:132487"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:132430"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27416" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1866 -- ca-certificates security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ca-certificates</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1866.html" ref_id="ELSA-2013-1866"/>
        <description>[2013.1.95-65.1]
- Update to CKBI 1.95 from NSS 3.15.3.1</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:39.488-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:17.701-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:47.028-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:18:46.929-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:18:46.929-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="ca-certificates is earlier than 0:2013.1.95-65.1.el6_5" test_ref="oval:org.mitre.oval:tst:128028"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27414" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0669 -- qt security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0669.html" ref_id="ELSA-2013-0669"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0254" ref_id="CVE-2013-0254"/>
        <description>[1:4.6.2-26]
- Resolves: CVE-2013-0254, QSharedMemory class created shared memory segments with insecure permissions</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:42.409-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:17.239-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:46.746-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:39:56.704-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:39:56.704-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qt is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129937"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129448"/>
          <criterion comment="qt-demos is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129773"/>
          <criterion comment="qt-devel is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129907"/>
          <criterion comment="qt-doc is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129939"/>
          <criterion comment="qt-examples is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129011"/>
          <criterion comment="qt-mysql is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129847"/>
          <criterion comment="qt-odbc is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129710"/>
          <criterion comment="qt-postgresql is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129935"/>
          <criterion comment="qt-sqlite is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129512"/>
          <criterion comment="qt-x11 is earlier than 0:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:129659"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27413" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2588 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2588.html" ref_id="ELSA-2013-2588"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4470" ref_id="CVE-2013-4470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6367" ref_id="CVE-2013-6367"/>
        <description>[2.6.39-400.211.3]
- ip6_output: do skb ufo init for peeked non ufo skb as well (Jiri Pirko) [Orabug: 17951806] {CVE-2013-4470}
- ip_output: do skb ufo init for peeked non ufo skb as well (Jiri Pirko) [Orabug: 17951818] {CVE-2013-4470}
- KVM: x86: Fix potential divide by 0 in lapic (CVE-2013-6367) (Andy Honig) [Orabug: 17951705] {CVE-2013-6367}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:49.014-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:17.050-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:46.624-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:127411"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:128157"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:127349"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:128243"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:127711"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.211.3.el5uek" test_ref="oval:org.mitre.oval:tst:127358"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:127387"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:127390"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:128310"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:128189"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:128162"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.211.3.el6uek" test_ref="oval:org.mitre.oval:tst:128019"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27412" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1156 -- httpd security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1156.html" ref_id="ELSA-2013-1156"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1896" ref_id="CVE-2013-1896"/>
        <description>[2.2.15-29.0.1.el6_4]
- replace index.html with Oracle's index page oracle_index.html
  update vstring in specfile

[2.2.15-29]
- mod_dav: add security fix for CVE-2013-1896 (#991368)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:14.910-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:16.801-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:46.464-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:20:36.244-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:20:36.244-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-82.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128888"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-82.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128676"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-82.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129264"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-82.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129243"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128972"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129219"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128861"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129240"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-29.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129119"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27409" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0159 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0159.html" ref_id="ELSA-2014-0159"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2929" ref_id="CVE-2013-2929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6381" ref_id="CVE-2013-6381"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263" ref_id="CVE-2013-7263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7265" ref_id="CVE-2013-7265"/>
        <description>[2.6.32-431.5.1]
- [net] sctp: fix checksum marking for outgoing packets (Daniel Borkmann) [1046041 1040385]
- [kernel] ptrace: Cleanup useless header (Aaron Tomlin) [1046043 1036312]
- [kernel] ptrace: kill BKL in ptrace syscall (Aaron Tomlin) [1046043 1036312]
- [fs] nfs: Prevent a 3-way deadlock between layoutreturn, open and state recovery (Steve Dickson) [1045094 1034487]
- [fs] nfs: Ensure that rmdir() waits for sillyrenames to complete (Steve Dickson) [1051395 1034348]
- [fs] nfs: wait on recovery for async session errors (Steve Dickson) [1051393 1030049]
- [fs] nfs: Re-use exit code in nfs4_async_handle_error() (Steve Dickson) [1051393 1030049]
- [fs] nfs: Update list of irrecoverable errors on DELEGRETURN (Steve Dickson) [1051393 1030049]
- [exec] ptrace: fix get_dumpable() incorrect tests (Petr Oros) [1039486 1039487] {CVE-2013-2929}
- [net] ipv6: router reachability probing (Jiri Benc) [1043779 1029585]
- [net] ipv6: remove the unnecessary statement in find_match() (Jiri Benc) [1043779 1029585]
- [net] ipv6: fix route selection if kernel is not compiled with CONFIG_IPV6_ROUTER_PREF (Jiri Benc) [1043779 1029585]
- [net] ipv6: Fix default route failover when CONFIG_IPV6_ROUTER_PREF=n (Jiri Benc) [1043779 1029585]
- [net] ipv6: probe routes asynchronous in rt6_probe (Jiri Benc) [1040826 1030094]
- [net] ndisc: Update neigh->updated with write lock (Jiri Benc) [1040826 1030094]
- [net] ipv6: prevent fib6_run_gc() contention (Jiri Benc) [1040826 1030094]
- [net] netfilter: push reasm skb through instead of original frag skbs (Jiri Pirko) [1049590 1011214]
- [net] ip6_output: fragment outgoing reassembled skb properly (Jiri Pirko) [1049590 1011214]
- [net] netfilter: nf_conntrack_ipv6: improve fragmentation handling (Jiri Pirko) [1049590 1011214]
- [net] ipv4: fix path MTU discovery with connection tracking (Jiri Pirko) [1049590 1011214]
- [net] ipv6: Make IP6CB(skb)->nhoff 16-bit (Jiri Pirko) [1049590 1011214]
- [edac] Add error decoding support for AMD Fam16h processors (Prarit Bhargava) [1051394 1020290]
- [netdrv] bnx2x: correct VF-PF channel locking scheme (Michal Schmidt) [1040498 1029203]
- [netdrv] bnx2x: handle known but unsupported VF messages (Michal Schmidt) [1040498 1029203]
- [netdrv] bnx2x: Lock DMAE when used by statistic flow (Michal Schmidt) [1040497 1029200]
- [net] ipv6: fix leaking uninitialized port number of offender sockaddr (Florian Westphal) [1035882 1035883] {CVE-2013-6405}
- [net] inet: fix addr_len/msg->msg_namelen assignment in recv_error functions (Florian Westphal) [1035882 1035883] {CVE-2013-6405}
- [net] inet: prevent leakage of uninitialized memory to user in recv syscalls (Florian Westphal) [1035882 1035883] {CVE-2013-6405}
- [net] ipvs: Add boundary check on ioctl arguments (Denys Vlasenko) [1030817 1030818] {CVE-2013-4588}
- [s390] qeth: avoid buffer overflow in snmp ioctl (Hendrik Brueckner) [1038935 1034266]
- [md] fix calculation of stacking limits on level change (Jes Sorensen) [1035347 1026864]
- [ata] ahci: fix turning on LEDs in ahci_start_port() (David Milburn) [1035339 1017105]
- [ata] libata: implement cross-port EH exclusion (David Milburn) [1035339 1017105]
- [ata] libata add ap to ata_wait_register and intro ata_msleep (David Milburn) [1035339 1017105]
- [netdrv] igb: Update link modes display in ethtool (Stefan Assmann) [1032389 1019578]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:29.393-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:16.237-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:46.138-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:56:52.976-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:56:52.976-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:127457"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:128036"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:127371"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:127940"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:127810"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:127757"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:127905"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:127995"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:128165"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:127959"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27408" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0097 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0097.html" ref_id="ELSA-2014-0097"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5878" ref_id="CVE-2013-5878"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5884" ref_id="CVE-2013-5884"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5896" ref_id="CVE-2013-5896"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5907" ref_id="CVE-2013-5907"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5910" ref_id="CVE-2013-5910"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0368" ref_id="CVE-2014-0368"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0373" ref_id="CVE-2014-0373"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0376" ref_id="CVE-2014-0376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0411" ref_id="CVE-2014-0411"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0416" ref_id="CVE-2014-0416"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0422" ref_id="CVE-2014-0422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0423" ref_id="CVE-2014-0423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0428" ref_id="CVE-2014-0428"/>
        <description>[1:1.6.0.1-3.1.13.0]
- updated to icedtea 1.13.1
 - http://blog.fuseyism.com/index.php/2014/01/23/security-icedtea-1-12-8-1-13-1-for-openjdk-6-released/
- updated to jdk6, b30,  21_jan_2014
 - https://openjdk6.java.net/OpenJDK6-B30-Changes.html
- adapted patch7 1.13_fixes.patch
- pre 2011 changelog moved to (till now  wrong) pre-2009-spec-changelog (rh1043611)
- added --disable-system-lcms to configure options to pass build
- adapted patch3 java-1.6.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#1050190</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:44.722-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:15.107-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:45.959-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:01:37.243-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:01:37.243-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127676"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128023"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127671"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128210"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-3.1.13.1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128002"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:128096"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:127928"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:128161"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:128205"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:128198"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27407" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1461 -- libproxy security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libproxy</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1461.html" ref_id="ELSA-2012-1461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4505" ref_id="CVE-2012-4505"/>
        <description>[0.3.0-3]
- Fix CVE-2012-4505</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:42.430-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:14.840-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:45.787-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:52:42.474-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:52:42.474-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libproxy is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:130840"/>
          <criterion comment="libproxy-bin is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:129866"/>
          <criterion comment="libproxy-devel is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:130831"/>
          <criterion comment="libproxy-gnome is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:130802"/>
          <criterion comment="libproxy-kde is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:129906"/>
          <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:130779"/>
          <criterion comment="libproxy-python is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:130856"/>
          <criterion comment="libproxy-webkit is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:130476"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27405" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0860 -- samba security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0860.html" ref_id="ELSA-2010-0860"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3069" ref_id="CVE-2010-3069"/>
        <description>[3.5.4-68.1]
- Security Release, fixes CVE-2010-3069
- resolves: #632264</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:26:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:03:58.534-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:14.241-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:45.308-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:07:34.586-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:07:34.586-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:134403"/>
          <criterion comment="libsmbclient is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:134378"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:134007"/>
          <criterion comment="samba-client is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:134456"/>
          <criterion comment="samba-common is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:134370"/>
          <criterion comment="samba-doc is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:134002"/>
          <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:133481"/>
          <criterion comment="samba-swat is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:134285"/>
          <criterion comment="samba-winbind is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:134390"/>
          <criterion comment="samba-winbind-clients is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:133972"/>
          <criterion comment="samba-winbind-devel is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:134251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27404" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0215 -- abrt and libreport security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>abrt</product>
          <product>libreport</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0215.html" ref_id="ELSA-2013-0215"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5659" ref_id="CVE-2012-5659"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5660" ref_id="CVE-2012-5660"/>
        <description>abrt
[2.0.8-6.0.1.el6_3.2]
- Add abrt-oracle-enterprise.patch to be product neutral
- Remove abrt-plugin-rhtsupport dependency for cli and desktop
- Make abrt Obsoletes/Provides abrt-plugin-rhtsupprot

[2.0.8-6.2]
- rebuild against new libreport (brew bug)
- Related: #895442

[2.0.8-6.1]
- don't follow symlinks
- Related: #895442

libreport
[2.0.9-5.0.1.el6_3.2]
- Add oracle-enterprise.patch
- Remove libreport-plugin-rhtsupport pkg

[2.0.9-5.2]
- in same cases we have to follow symlinks
- Related: #895442

[2.0.9-5.1]
- don't follow symlinks
- Resolves: #895442</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:37.542-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:13.893-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:45.118-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:05:54.354-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:05:54.354-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="abrt is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130081"/>
          <criterion comment="libreport is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130505"/>
          <criterion comment="abrt-addon-ccpp is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130553"/>
          <criterion comment="abrt-addon-kerneloops is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130474"/>
          <criterion comment="abrt-addon-python is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130174"/>
          <criterion comment="abrt-addon-vmcore is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130549"/>
          <criterion comment="abrt-cli is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130365"/>
          <criterion comment="abrt-desktop is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130345"/>
          <criterion comment="abrt-devel is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130518"/>
          <criterion comment="abrt-gui is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130214"/>
          <criterion comment="abrt-libs is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130344"/>
          <criterion comment="abrt-tui is earlier than 0:2.0.8-6.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:129877"/>
          <criterion comment="libreport-cli is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130129"/>
          <criterion comment="libreport-devel is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130298"/>
          <criterion comment="libreport-gtk is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130582"/>
          <criterion comment="libreport-gtk-devel is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130583"/>
          <criterion comment="libreport-newt is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:129910"/>
          <criterion comment="libreport-plugin-bugzilla is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130383"/>
          <criterion comment="libreport-plugin-kerneloops is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130513"/>
          <criterion comment="libreport-plugin-logger is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130363"/>
          <criterion comment="libreport-plugin-mailx is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130559"/>
          <criterion comment="libreport-plugin-reportuploader is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130419"/>
          <criterion comment="libreport-python is earlier than 0:2.0.9-5.0.1.el6_3.2" test_ref="oval:org.mitre.oval:tst:130536"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27402" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1173 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1173.html" ref_id="ELSA-2013-1173"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6544" ref_id="CVE-2012-6544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2206" ref_id="CVE-2013-2206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2224" ref_id="CVE-2013-2224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2232" ref_id="CVE-2013-2232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2237" ref_id="CVE-2013-2237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2146" ref_id="CVE-2013-2146"/>
        <description>[2.6.32-358.18.1]
- [x86] perf/x86: Fix offcore_rsp valid mask for SNB/IVB (Nikola Pajkovsky) [971314 971315] {CVE-2013-2146}
- [net] br: fix schedule while atomic issue in br_features_recompute() (Jiri Pirko) [990464 980876]
- [scsi] isci: Fix a race condition in the SSP task management path (David Milburn) [990470 978609]
- [bluetooth] L2CAP - Fix info leak via getsockname() (Jacob Tanenbaum) [922417 922418] {CVE-2012-6544}
- [bluetooth] HCI - Fix info leak in getsockopt() (Jacob Tanenbaum) [922417 922418] {CVE-2012-6544}
- [net] tuntap: initialize vlan_features (Vlad Yasevich) [984524 951458]
- [net] af_key: initialize satype in key_notify_policy_flush() (Thomas Graf) [981225 981227] {CVE-2013-2237}
- [usb] uhci: fix for suspend of virtual HP controller (Gopal) [982697 960026]
- [usb] uhci: Remove PCI dependencies from uhci-hub (Gopal) [982697 960026]
- [netdrv] bnx2x: Change MDIO clock settings (Michal Schmidt) [982116 901747]
- [scsi] st: Take additional queue ref in st_probe (Tomas Henzl) [979293 927988]
- [kernel] audit: wait_for_auditd() should use TASK_UNINTERRUPTIBLE (Oleg Nesterov) [982472 962976]
- [kernel] audit: avoid negative sleep durations (Oleg Nesterov) [982472 962976]
- [fs] ext4/jbd2: dont wait (forever) for stale tid caused by wraparound (Eric Sandeen) [963557 955807]
- [fs] jbd: dont wait (forever) for stale tid caused by wraparound (Eric Sandeen) [963557 955807]
- [fs] ext4: fix waiting and sending of a barrier in ext4_sync_file() (Eric Sandeen) [963557 955807]
- [fs] jbd2: Add function jbd2_trans_will_send_data_barrier() (Eric Sandeen) [963557 955807]
- [fs] jbd2: fix sending of data flush on journal commit (Eric Sandeen) [963557 955807]
- [fs] ext4: fix fdatasync() for files with only i_size changes (Eric Sandeen) [963557 955807]
- [fs] ext4: Initialize fsync transaction ids in ext4_new_inode() (Eric Sandeen) [963557 955807]
- [fs] ext4: Rewrite __jbd2_log_start_commit logic to match upstream (Eric Sandeen) [963557 955807]
- [net] bridge: Set vlan_features to allow offloads on vlans (Vlad Yasevich) [984524 951458]
- [virt] virtio-net: initialize vlan_features (Vlad Yasevich) [984524 951458]
- [mm] swap: avoid read_swap_cache_async() race to deadlock while waiting on discard I/O completion (Rafael Aquini) [977668 827548]
- [dma] ioat: Fix excessive CPU utilization (John Feeney) [982758 883575]
- [fs] vfs: revert most of dcache remove d_mounted (Ian Kent) [974597 907512]
- [fs] xfs: don't free EFIs before the EFDs are committed (Carlos Maiolino) [975578 947582]
- [fs] xfs: pass shutdown method into xfs_trans_ail_delete_bulk (Carlos Maiolino) [975576 805407]
- [net] ipv6: bind() use stronger condition for bind_conflict (Flavio Leitner) [989923 917872]
- [net] tcp: bind() use stronger condition for bind_conflict (Flavio Leitner) [977680 894683]
- [x86] remove BUG_ON(TS_USEDFPU) in __sanitize_i387_state() (Oleg Nesterov) [956054 920445]
- [fs] coredump: ensure the fpu state is flushed for proper multi-threaded core dump (Oleg Nesterov) [956054 920445]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:10.236-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:13.434-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:44.834-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:22:34.444-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:22:34.444-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:128832"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:129036"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:129108"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:128722"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:129062"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:128664"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:128976"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:128237"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:128763"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27401" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1268 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1268.html" ref_id="ELSA-2013-1268"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1718" ref_id="CVE-2013-1718"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1722" ref_id="CVE-2013-1722"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1725" ref_id="CVE-2013-1725"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1730" ref_id="CVE-2013-1730"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1732" ref_id="CVE-2013-1732"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1735" ref_id="CVE-2013-1735"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1736" ref_id="CVE-2013-1736"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1737" ref_id="CVE-2013-1737"/>
        <description>firefox
[17.0.9-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.9-1]
- Update to 17.0.9 ESR

[17.0.8-4]
- Added fix for mozbz#601442 - Support the extensions.getAddons.showPane
  pref again in the Add-ons Manager UI, a part of rhbz#818636 fix.

[17.0.8-3]
- Fixed rhbz#818636 - Firefox allows install of addons,
  disregarding xpinstall.enabled flag set as false.

[17.0.8-2]
- Updated manual page

xulrunner
[17.0.9-1.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.9-1]
- Update to 17.0.9 ESR

[17.0.8-5]
- Fixed mozbz#633001 - Cannot open ipv6 address with self-signed certificate

[17.0.8-4]
- Fixed rhbz#818636 - Firefox allows install of addons,
  disregarding xpinstall.enabled flag set as false.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:55.235-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:13.293-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:44.720-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:02:25.345-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:02:25.345-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.9-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128975"/>
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128755"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129087"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.9-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128136"/>
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128426"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27400" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1064 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1064.html" ref_id="ELSA-2012-1064"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2744" ref_id="CVE-2012-2744"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2745" ref_id="CVE-2012-2745"/>
        <description>[2.6.32-279.1.1.el6]
- [kernel] Prevent keyctl new_session from causing a panic (David Howells) [833433 827424] {CVE-2012-2745}
- [net] ipv6/netfilter: fix null pointer dereference in nf_ct_frag6_reasm() (Petr Matousek) [833410 833412] {CVE-2012-2744}
- [fs] nfs: Map minor mismatch error to protocol not support error (Steve Dickson) [832365 796352]
- [fs] ext4: Fix overflow caused by missing cast in ext4_fallocate() (Lukas Czerner) [833034 830209]
- [ata] libata: Add 2GB ATA Flash Disk/ADMA428M to DMA blacklist (Prarit Bhargava) [832363 812904]
- [netdrv] r8169: fix typo in firmware filenames (Ivan Vecera) [832359 829211]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:13.758-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:13.023-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:44.561-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:51:03.663-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:51:03.663-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:131571"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:131207"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:131017"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:130697"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:131632"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:131559"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:131403"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:131391"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:131334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27399" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0623 -- tomcat6 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0623.html" ref_id="ELSA-2013-0623"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5885" ref_id="CVE-2012-5885"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5887" ref_id="CVE-2012-5887"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5886" ref_id="CVE-2012-5886"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3546" ref_id="CVE-2012-3546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4534" ref_id="CVE-2012-4534"/>
        <description>[0:6.0.24-52]
- Related: rhbz 882010 rhbz 883692 rhbz 883705
- Javadoc generation did not work. Using targetrhel-6.4.Z-noarch-candidate
- to avoid building on ppc64, ppc, and x390x.

[0:6.0.24-50]
- Resolves: rhbz 882010 CVE-2012-3439 CVE-2012-5885 CVE-2012-5886 CVE-2012-5887
- three DIGEST authentication issues
- Resolves: rhbz 883692 CVE-2012-4534 Denial of service when using
- SSL NIO sendfile
- Resolves: rhbz 883705 CVE-2012-3546 Bypass of Realm security constraints</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:50.941-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:12.824-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:44.392-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:43:34.560-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:43:34.560-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:129105"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:129092"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:129516"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:129931"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:129883"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:130064"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:130010"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:130065"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:129983"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27397" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0395 -- gdm security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gdm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0395.html" ref_id="ELSA-2011-0395"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0727" ref_id="CVE-2011-0727"/>
        <description>[2.30.4-21.0.2.el6_0.1]
- Added oracle-enterprise.patch to show oracle-release contents.

[2.30.4-21.1]
- Fix CVE-2011-0727</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:50.994-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:12.354-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:44.015-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:27:47.386-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:27:47.386-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gdm is earlier than 0:2.30.4-21.0.2.el6_0.1" test_ref="oval:org.mitre.oval:tst:133933"/>
          <criterion comment="gdm-libs is earlier than 0:2.30.4-21.0.2.el6_0.1" test_ref="oval:org.mitre.oval:tst:134152"/>
          <criterion comment="gdm-plugin-fingerprint is earlier than 0:2.30.4-21.0.2.el6_0.1" test_ref="oval:org.mitre.oval:tst:133989"/>
          <criterion comment="gdm-plugin-smartcard is earlier than 0:2.30.4-21.0.2.el6_0.1" test_ref="oval:org.mitre.oval:tst:133959"/>
          <criterion comment="gdm-user-switch-applet is earlier than 0:2.30.4-21.0.2.el6_0.1" test_ref="oval:org.mitre.oval:tst:133956"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27396" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1269 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1269.html" ref_id="ELSA-2013-1269"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1718" ref_id="CVE-2013-1718"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1722" ref_id="CVE-2013-1722"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1725" ref_id="CVE-2013-1725"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1730" ref_id="CVE-2013-1730"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1732" ref_id="CVE-2013-1732"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1735" ref_id="CVE-2013-1735"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1736" ref_id="CVE-2013-1736"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1737" ref_id="CVE-2013-1737"/>
        <description>[17.0.9-1.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.9-1]
- Update to 17.0.9 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:21.601-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:11.601-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:43.589-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:42:29.985-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:42:29.985-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128858"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128433"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27395" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0512 -- httpd security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0512.html" ref_id="ELSA-2013-0512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2687" ref_id="CVE-2012-2687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0455" ref_id="CVE-2008-0455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4557" ref_id="CVE-2012-4557"/>
        <description>[2.2.15-26.0.1.el6]
- replace index.html with Oracle's index page oracle_index.html
  update vstring in specfile

[2.2.15-26]
- htcacheclean: exit with code 4 also for 'restart' action (#805810)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:38.577-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:11.238-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:43.147-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:14:25.955-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:14:25.955-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="httpd is earlier than 0:2.2.15-26.0.1.el6" test_ref="oval:org.mitre.oval:tst:129533"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.15-26.0.1.el6" test_ref="oval:org.mitre.oval:tst:130337"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.15-26.0.1.el6" test_ref="oval:org.mitre.oval:tst:130271"/>
          <criterion comment="httpd-tools is earlier than 0:2.2.15-26.0.1.el6" test_ref="oval:org.mitre.oval:tst:130195"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.15-26.0.1.el6" test_ref="oval:org.mitre.oval:tst:130045"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27394" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1081 -- sudo security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1081.html" ref_id="ELSA-2012-1081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2337" ref_id="CVE-2012-2337"/>
        <description>[1.7.4p5-12]
- added patch for CVE-2012-2337
  Resolves: rhbz#829756</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:31.160-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:10.998-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:42.872-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:53:41.846-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:53:41.846-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8" test_ref="oval:org.mitre.oval:tst:131475"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="sudo is earlier than 0:1.7.4p5-12.el6_3" test_ref="oval:org.mitre.oval:tst:131238"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27392" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0222 -- libtiff security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0222.html" ref_id="ELSA-2014-0222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2596" ref_id="CVE-2010-2596"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1960" ref_id="CVE-2013-1960"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1961" ref_id="CVE-2013-1961"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4231" ref_id="CVE-2013-4231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4232" ref_id="CVE-2013-4232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4243" ref_id="CVE-2013-4243"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4244" ref_id="CVE-2013-4244"/>
        <description>[3.9.4-10]
- Resolves: #1063464. Several CVEs for libtiff</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:36.018-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:10.046-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:42.486-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:33:06.032-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:33:06.032-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libtiff is earlier than 0:3.9.4-10.el6_5" test_ref="oval:org.mitre.oval:tst:127968"/>
          <criterion comment="libtiff-devel is earlier than 0:3.9.4-10.el6_5" test_ref="oval:org.mitre.oval:tst:128001"/>
          <criterion comment="libtiff-static is earlier than 0:3.9.4-10.el6_5" test_ref="oval:org.mitre.oval:tst:127981"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27391" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0448 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0448.html" ref_id="ELSA-2014-0448"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1518" ref_id="CVE-2014-1518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1523" ref_id="CVE-2014-1523"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1524" ref_id="CVE-2014-1524"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1529" ref_id="CVE-2014-1529"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1530" ref_id="CVE-2014-1530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1531" ref_id="CVE-2014-1531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1532" ref_id="CVE-2014-1532"/>
        <description>[24.5.0-1.0.1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one
- Build with nspr-devel >= 4.10.0 to fix build failure

[24.5.0-1]
- Update to 24.5.0 ESR

[24.4.0-3]
- Added a workaround for Bug 1054242 - RHEVM: Extremely high memory
  usage in Firefox 24 ESR on RHEL 6.5

[24.4.0-2]
- fixed rhbz#1067343 - Broken languagepack configuration
  after firefox update</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:34.964-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:09.931-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:42.252-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:38:24.547-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:38:24.547-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127560"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127721"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27389" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0896 -- qemu-kvm security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0896.html" ref_id="ELSA-2013-0896"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2007" ref_id="CVE-2013-2007"/>
        <description>[0.12.1.2-2.355.el6_4.5]
- kvm-e1000-fix-link-down-handling-with-auto-negotiation.patch [bz#907716]
- kvm-e1000-unbreak-the-guest-network-when-migration-to-RH.patch [bz#907716]
- kvm-reimplement-error_setg-and-error_setg_errno-for-RHEL.patch [bz#957056]
- kvm-qga-set-umask-0077-when-daemonizing-CVE-2013-2007.patch [bz#957056]
- kvm-qga-distinguish-binary-modes-in-guest_file_open_mode.patch [bz#957056]
- kvm-qga-unlink-just-created-guest-file-if-fchmod-or-fdop.patch [bz#957056]
- Resolves: bz#907716
  (use set_link  to change rtl8139 and e1000 network card's status but fail to make effectively after reboot guest)
- Resolves: bz#957056
  (CVE-2013-2007 qemu: guest agent creates files with insecure permissions in deamon mode [rhel-6.4.z])

[0.12.1.2-2.355.el6_4.4]
- kvm-virtio-balloon-fix-integer-overflow-in-BALLOON_CHANG.patch [bz#958750]
- Resolves: bz#958750
  (QMP event shows incorrect balloon value when balloon size is grater than or equal to 4G)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:39.260-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:09.525-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:41.921-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:47:01.084-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:47:01.084-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:129412"/>
          <criterion comment="qemu-guest-agent is earlier than 0:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:129423"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27388" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2587 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>dtrace-modules-3.8.13-16.2.3.el6uek-provider-headers</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2587.html" ref_id="ELSA-2013-2587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4470" ref_id="CVE-2013-4470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6367" ref_id="CVE-2013-6367"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6368" ref_id="CVE-2013-6368"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6376" ref_id="CVE-2013-6376"/>
        <description>kernel-uek
[3.8.13-16.2.3.el6uek]
- ip_output: do skb ufo init for peeked non ufo skb as well (Jiri Pirko) [Orabug: 17951078] {CVE-2013-4470}
- ip6_output: do skb ufo init for peeked non ufo skb as well (Jiri Pirko) [Orabug: 17951080] {CVE-2013-4470}
- KVM: x86: fix guest-initiated crash with x2apic (CVE-2013-6376) (Gleb Natapov) [Orabug: 17951067] {CVE-2013-6376}
- KVM: x86: Convert vapic synchronization to _cached functions (CVE-2013-6368) (Andy Honig) [Orabug: 17951071] {CVE-2013-6368}
- KVM: x86: Fix potential divide by 0 in lapic (CVE-2013-6367) (Andy Honig) [Orabug: 17951073] {CVE-2013-6367}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:37.753-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:09.270-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:41.708-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35354 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:57.492-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:19.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-16.2.3.el6uek is earlier than 0:0.4.1-3.el6" test_ref="oval:org.mitre.oval:tst:127871"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-16.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:128153"/>
          <criterion comment="dtrace-modules-3.8.13-16.2.3.el6uek-headers is earlier than 0:0.4.1-3.el6" test_ref="oval:org.mitre.oval:tst:127821"/>
          <criterion comment="dtrace-modules-3.8.13-16.2.3.el6uek-provider-headers is earlier than 0:0.4.1-3.el6" test_ref="oval:org.mitre.oval:tst:128223"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-16.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:127907"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-16.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:128185"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-16.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:127874"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-16.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:128009"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-16.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:128260"/>
          <criterion comment="kernel-uek-headers is earlier than 0:3.8.13-16.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:128171"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27387" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1537 -- augeas security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>augeas</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1537.html" ref_id="ELSA-2013-1537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0786" ref_id="CVE-2012-0786"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0787" ref_id="CVE-2012-0787"/>
        <description>[1.0.0-5]

- Don't package lenses in tests/ subdirectory.

  related: rhbz#817753</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:49.315-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:08.988-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:41.574-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="augeas is earlier than 0:1.0.0-5.el6" test_ref="oval:org.mitre.oval:tst:128040"/>
          <criterion comment="augeas-devel is earlier than 0:1.0.0-5.el6" test_ref="oval:org.mitre.oval:tst:128514"/>
          <criterion comment="augeas-libs is earlier than 0:1.0.0-5.el6" test_ref="oval:org.mitre.oval:tst:127549"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27386" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0342 -- wireshark security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0342.html" ref_id="ELSA-2014-0342"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6336" ref_id="CVE-2013-6336"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6337" ref_id="CVE-2013-6337"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6338" ref_id="CVE-2013-6338"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6339" ref_id="CVE-2013-6339"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6340" ref_id="CVE-2013-6340"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7112" ref_id="CVE-2013-7112"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7114" ref_id="CVE-2013-7114"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2281" ref_id="CVE-2014-2281"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2283" ref_id="CVE-2014-2283"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2299" ref_id="CVE-2014-2299"/>
        <description>[1.8.10-7.0.1.el6]
- Add oracle-ocfs2-network.patch to allow disassembly of OCFS2 interconnect

[1.8.10-7]
- security patches
- Resolves: CVE-2013-6337

[1.8.10-6]
- security patches
- Resolves: CVE-2014-2281
            CVE-2014-2283
            CVE-2014-2299

[1.8.10-5]
- security patches
- Resolves: CVE-2013-6336
            CVE-2013-6338
            CVE-2013-6339
            CVE-2013-6340
            CVE-2013-7112
            CVE-2013-7114</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:33.669-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:08.326-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:41.216-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:13:53.662-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:13:53.662-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="wireshark is earlier than 0:1.8.10-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127770"/>
          <criterion comment="wireshark-devel is earlier than 0:1.8.10-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127875"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.8.10-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127846"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27385" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0217 -- mingw32-libxml2 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mingw32-libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0217.html" ref_id="ELSA-2013-0217"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0841" ref_id="CVE-2012-0841"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3905" ref_id="CVE-2011-3905"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3919" ref_id="CVE-2011-3919"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4008" ref_id="CVE-2010-4008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4494" ref_id="CVE-2010-4494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0216" ref_id="CVE-2011-0216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1944" ref_id="CVE-2011-1944"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2821" ref_id="CVE-2011-2821"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2834" ref_id="CVE-2011-2834"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3102" ref_id="CVE-2011-3102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5134" ref_id="CVE-2012-5134"/>
        <description>[2.7.6-6]
- Synchronize patch-set with mainline-version.
- Bump version to 5, 6.
  Related: rhbz#891477

[2.7.6-4]                                      
- Change release number to 4.
- Added patch libxml2-Fix-an-off-by-one-pointer-access.patch
- Added patch libxml2-Fix-a-segfault-on-XSD-validation-on-pattern-error.patch
- Added patch libxml2-Fix-entities-local-buffers-size-problems.patch
- Added patch libxml2-gnome-bug-561340-fix.patch
- Added patch for CVE-2012-0841
- Added patch for CVE-2011-0216
- Added patch for CVE-2011-2834
- Added patch for CVE-2011-3919
- Added patch for CVE-2011-1944
- Added patch for CVE-2011-3905
  Related: rhbz#891477</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:50.526-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:07.374-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:40.684-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:41:30.969-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:41:30.969-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mingw32-libxml2 is earlier than 0:2.7.6-6.el6_3" test_ref="oval:org.mitre.oval:tst:130261"/>
          <criterion comment="mingw32-libxml2-static is earlier than 0:2.7.6-6.el6_3" test_ref="oval:org.mitre.oval:tst:130349"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27383" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2538 -- unbreakable enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2538.html" ref_id="ELSA-2013-2538"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0914" ref_id="CVE-2013-0914"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3222" ref_id="CVE-2013-3222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3224" ref_id="CVE-2013-3224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6548" ref_id="CVE-2012-6548"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2634" ref_id="CVE-2013-2634"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2635" ref_id="CVE-2013-2635"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2852" ref_id="CVE-2013-2852"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3225" ref_id="CVE-2013-3225"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3301" ref_id="CVE-2013-3301"/>
        <description>[2.6.39-400.109.3]
- Revert 'be2net: enable interrupts in probe' (Jerry Snitselaar) [Orabug: 17179597]

[2.6.39-400.109.2]
- be2net: enable interrupts in probe (Jerry Snitselaar) [Orabug: 17080364] 
- Bluetooth: RFCOMM - Fix missing msg_namelen update in rfcomm_sock_recvmsg() (Mathias Krause) [Orabug: 17173830] {CVE-2013-3225}
- Bluetooth: fix possible info leak in bt_sock_recvmsg() (Mathias Krause) [Orabug: 17173830] {CVE-2013-3224}
- atm: update msg_namelen in vcc_recvmsg() (Mathias Krause) [Orabug: 17173830] {CVE-2013-3222}
- rtnl: fix info leak on RTM_GETLINK request for VF devices (Mathias Krause) [Orabug: 17173830] {CVE-2013-2635}
- dcbnl: fix various netlink info leaks (Mathias Krause) [Orabug: 17173830] {CVE-2013-2634}
- udf: avoid info leak on export (Mathias Krause) [Orabug: 17173830] {CVE-2012-6548}
- tracing: Fix possible NULL pointer dereferences (Namhyung Kim) [Orabug: 17173830] {CVE-2013-3301}
- b43: stop format string leaking into error msgs (Kees Cook) [Orabug: 17173830] {CVE-2013-2852}
- signal: always clear sa_restorer on execve (Kees Cook) [Orabug: 17173830] {CVE-2013-0914}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:38.113-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:06.205-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:40.032-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129159"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129077"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129258"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129022"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:129147"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.3.el5uek" test_ref="oval:org.mitre.oval:tst:128993"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:128924"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:129202"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:128950"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:129213"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:129279"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.3.el6uek" test_ref="oval:org.mitre.oval:tst:128551"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27382" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0219 -- mysql security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0219.html" ref_id="ELSA-2013-0219"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0572" ref_id="CVE-2012-0572"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0574" ref_id="CVE-2012-0574"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1702" ref_id="CVE-2012-1702"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1705" ref_id="CVE-2012-1705"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0375" ref_id="CVE-2013-0375"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0383" ref_id="CVE-2013-0383"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0384" ref_id="CVE-2013-0384"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0385" ref_id="CVE-2013-0385"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0389" ref_id="CVE-2013-0389"/>
        <description>[5.1.67-1]
- Update to 5.1.67, for assorted upstream bugfixes including
  CVEs announced in January 2013
Resolves: #901380</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:31.120-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:05.379-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:39.656-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:58:11.162-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:58:11.162-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:130577"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:130551"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:130153"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:130395"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:130548"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:130497"/>
          <criterion comment="mysql-server is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:130401"/>
          <criterion comment="mysql-test is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:130452"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27380" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0683 -- bind-dyndb-ldap security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind-dyndb-ldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0683.html" ref_id="ELSA-2012-0683"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2134" ref_id="CVE-2012-2134"/>
        <description>[0.2.0-7.1]
- fix for CVE-2012-2134</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:17.068-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:04.871-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:39.374-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:00:10.896-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:00:10.896-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="bind-dyndb-ldap is earlier than 0:0.2.0-7.el6_2.1" test_ref="oval:org.mitre.oval:tst:132061"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27379" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1701 -- sudo security, bug fix and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1701.html" ref_id="ELSA-2013-1701"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1775" ref_id="CVE-2013-1775"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2776" ref_id="CVE-2013-2776"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2777" ref_id="CVE-2013-2777"/>
        <description>[1.8.6p3-12]

- added patches for CVE-2013-1775 CVE-2013-2777 CVE-2013-2776

  Resolves: rhbz#1015355</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:20.058-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:04.426-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:39.248-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="sudo is earlier than 0:1.8.6p3-12.el6" test_ref="oval:org.mitre.oval:tst:128589"/>
          <criterion comment="sudo-devel is earlier than 0:1.8.6p3-12.el6" test_ref="oval:org.mitre.oval:tst:128635"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27378" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2575 -- unbreakable enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2575.html" ref_id="ELSA-2013-2575"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4162" ref_id="CVE-2013-4162"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4299" ref_id="CVE-2013-4299"/>
        <description>kernel-uek
[2.6.32-400.33.2]
- dm snapshot: fix data corruption (Mikulas Patocka) [Orabug: 17618900] {CVE-2013-4299}
- ipv6: call udp_push_pending_frames when uncorking a socket with AF_INET pending data (Hannes Frederic Sowa) [Orabug: 17618897] {CVE-2013-4162}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:17.471-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:04.133-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:39.117-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35446 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:56.196-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:18.555-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128860"/>
            <criterion comment="mlnx_en-2.6.32-400.33.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129025"/>
            <criterion comment="ofa-2.6.32-400.33.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128995"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128254"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128987"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128148"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128679"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128911"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.2.el5uek" test_ref="oval:org.mitre.oval:tst:128846"/>
            <criterion comment="mlnx_en-2.6.32-400.33.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128915"/>
            <criterion comment="ofa-2.6.32-400.33.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128957"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128829"/>
            <criterion comment="mlnx_en-2.6.32-400.33.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128482"/>
            <criterion comment="ofa-2.6.32-400.33.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128956"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128396"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128998"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128882"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:129055"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128575"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.2.el6uek" test_ref="oval:org.mitre.oval:tst:128529"/>
            <criterion comment="mlnx_en-2.6.32-400.33.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128869"/>
            <criterion comment="ofa-2.6.32-400.33.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128994"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27377" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0511 -- pki-core security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pki-core</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0511.html" ref_id="ELSA-2013-0511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4543" ref_id="CVE-2012-4543"/>
        <description>[9.0.3-30]
- Resolves #902474 - upgrading IPA from 2.2 to 3.0 sees certmonger errors

[9.0.3-29]
- Resolves #891985 - Increase FreeIPA root CA validity

[9.0.3-28]
- Resolves #885790 - Multiple cross-site scripting flaws
  by displaying CRL or processing profile

[9.0.3-27]
- Resolves #867640 - ipa-replica-install Configuration of CA failed
  by REVERTING #819111 - Non-existent container breaks replication

[9.0.3-26]
- Resolves #844459 - Increase audit cert renewal range to 2 years (mharmsen)
- Resolves #841663 - serial number incorrectly cast from BigInt to integer in
  installation wizard (mharmsen)
- Resolves #858864 - create/ identify a mechanism for clients to determine that
  the pki subsystem is up (alee)

[9.0.3-25]
- Resolves #819111 - Non-existent container breaks replication</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:36.241-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:03.902-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:38.974-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:42:40.688-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:42:40.688-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pki-core is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:129962"/>
          <criterion comment="pki-ca is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:130036"/>
          <criterion comment="pki-common is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:129899"/>
          <criterion comment="pki-common-javadoc is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:130283"/>
          <criterion comment="pki-java-tools is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:130049"/>
          <criterion comment="pki-java-tools-javadoc is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:130155"/>
          <criterion comment="pki-native-tools is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:130008"/>
          <criterion comment="pki-selinux is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:130320"/>
          <criterion comment="pki-setup is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:129984"/>
          <criterion comment="pki-silent is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:130126"/>
          <criterion comment="pki-symkey is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:129381"/>
          <criterion comment="pki-util is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:130292"/>
          <criterion comment="pki-util-javadoc is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:130300"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27374" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0475 -- tomcat6 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0475.html" ref_id="ELSA-2012-0475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4858" ref_id="CVE-2011-4858"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022" ref_id="CVE-2012-0022"/>
        <description>[0:6.0.24-36]
- Resolves: CVE-2012-0022 regression. Changes made to patch file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:13.992-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:03.023-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:38.328-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:53:59.301-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:53:59.301-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:132568"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:132443"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:132569"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:132220"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:131893"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:132524"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:132457"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:132104"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:132567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27373" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0127 -- librsvg2 security update (updated 02/05/2014) (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>librsvg2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0127.html" ref_id="ELSA-2014-0127"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1881" ref_id="CVE-2013-1881"/>
        <description>[2.26.0-6.3]

- Fix add-permission-check.patch to update all rsvg_pixbuf_new_from_href()

  callers



[2.26.0-6.1]

- Fix build by linking in -lm

- io: Implement strict network policy (CVE-2013-1881)

  Resolves: #1049155



[2.26.0-6]

- Store node type separately in RsvgNode (CVE-2011-3146)

   Resolves: #735267</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:24.515-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:02.845-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:38.243-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:20:46.872-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:20:46.872-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="librsvg2 is earlier than 0:2.26.0-6.el6_5.2" test_ref="oval:org.mitre.oval:tst:127984"/>
          <criterion comment="librsvg2 is earlier than 0:2.26.0-6.el6_5.3" test_ref="oval:org.mitre.oval:tst:128046"/>
          <criterion comment="librsvg2-devel is earlier than 0:2.26.0-6.el6_5.2" test_ref="oval:org.mitre.oval:tst:128029"/>
          <criterion comment="librsvg2-devel is earlier than 0:2.26.0-6.el6_5.3" test_ref="oval:org.mitre.oval:tst:127876"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27371" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1441 -- rubygems security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>rubygems</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1441.html" ref_id="ELSA-2013-1441"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2125" ref_id="CVE-2012-2125"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2126" ref_id="CVE-2012-2126"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4287" ref_id="CVE-2013-4287"/>
        <description>[1.3.7-4]
- Remove regexp backtracing (CVE-2013-4363).
  - Related: rhbz#1002838.

[1.3.7-3]
- Fix insecure connection to SSL repository (CVE-2012-2125, CVE-2012-2126).
  - Related: rhbz#1002838.

[1.3.7-2]
- Fix algorithmic complexity vulnerability (CVE-2013-4287).
  - Resolves: rhbz#1002838.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:25.993-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:02.534-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:38.096-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:39:12.315-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:39:12.315-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="rubygems is earlier than 0:1.3.7-4.el6_4" test_ref="oval:org.mitre.oval:tst:128585"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27369" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0133 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0133.html" ref_id="ELSA-2014-0133"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1477" ref_id="CVE-2014-1477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1479" ref_id="CVE-2014-1479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1481" ref_id="CVE-2014-1481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1482" ref_id="CVE-2014-1482"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1486" ref_id="CVE-2014-1486"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1487" ref_id="CVE-2014-1487"/>
        <description>[24.3.0-2.0.1.el6_5]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Make sure build with nspr-devel >= 4.10.0

[24.3.0-2]
- Update to 24.3.0 ESR Build 2

[24.3.0-1]
- Update to 24.3.0

[24.2.0-2]
- Fixed requested nspr/nss versions</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:26.226-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:02.254-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.868-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:03:56.957-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:03:56.957-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127714"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128069"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27366" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1812 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1812.html" ref_id="ELSA-2013-1812"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5609" ref_id="CVE-2013-5609"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5612" ref_id="CVE-2013-5612"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5613" ref_id="CVE-2013-5613"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5614" ref_id="CVE-2013-5614"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5616" ref_id="CVE-2013-5616"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5618" ref_id="CVE-2013-5618"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6671" ref_id="CVE-2013-6671"/>
        <description>[24.2.0-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one
- Build with nspr-devel >= 4.10.0 to fix build failure

[24.2.0-1]
- Update to 24.2.0 ESR

[24.1.0-4]
- Fixed mozbz#938730 - avoid mix of memory allocators (crashes)
  when using system sqlite

[24.1.0-3]
- Fixed locale pickup (rhbz#1034541)

[24.1.0-2]
- Fixed package reinstall issue

[24.1.0-1]
- Update to 24.1.0 ESR

[24.0-0.1]
- Update to 24.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:26.674-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:00.881-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.525-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:29:48.438-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:29:48.438-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128312"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127750"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27365" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0293 -- udisks security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>udisks</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0293.html" ref_id="ELSA-2014-0293"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0004" ref_id="CVE-2014-0004"/>
        <description>[1.0.1-7.el6_5]
- Make sure doc subpackage is noarch

[1.0.1-6.el6_5]
- Put devel-docs in a separate package (related: rhbz#1070145) .

[1.0.1-5.el6_5]
- Related: rhbz#1070145.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:10.509-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:00.720-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.395-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:32:31.752-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:32:31.752-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="udisks is earlier than 0:1.0.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:127858"/>
          <criterion comment="udisks-devel is earlier than 0:1.0.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:127760"/>
          <criterion comment="udisks-devel-docs is earlier than 0:1.0.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:127986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27364" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0697 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0697.html" ref_id="ELSA-2013-0697"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0800" ref_id="CVE-2013-0800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0796" ref_id="CVE-2013-0796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0788" ref_id="CVE-2013-0788"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0795" ref_id="CVE-2013-0795"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0793" ref_id="CVE-2013-0793"/>
        <description>[17.0.5-1.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.5-1]
- Update to 17.0.5 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:36.547-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:04:00.250-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:37.210-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:12:20.048-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:12:20.048-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129842"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129733"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27363" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2543 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2543.html" ref_id="ELSA-2013-2543"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6544" ref_id="CVE-2012-6544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2206" ref_id="CVE-2013-2206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2232" ref_id="CVE-2013-2232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2237" ref_id="CVE-2013-2237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1059" ref_id="CVE-2013-1059"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2851" ref_id="CVE-2013-2851"/>
        <description>[2.6.39-400.109.6]
- block: do not pass disk names as format strings (Kees Cook) [Orabug: 17230083] {CVE-2013-2851}
- libceph: Fix NULL pointer dereference in auth client code (Tyler Hicks) [Orabug: 17230108] {CVE-2013-1059}
- ipv6: ip6_sk_dst_check() must not assume ipv6 dst (Eric Dumazet) [Orabug: 17371078] {CVE-2013-2232}
- af_key: initialize satype in key_notify_policy_flush() (Nicolas Dichtel) [Orabug: 17370788] {CVE-2013-2237}
- Bluetooth: HCI - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17370892] {CVE-2012-6544}
- Bluetooth: L2CAP - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17371050] {CVE-2012-6544}
- Bluetooth: HCI - Fix info leak in getsockopt(HCI_FILTER) (Mathias Krause) [Orabug: 17371065] {CVE-2012-6544}
- sctp: Use correct sideffect command in duplicate cookie handling (Vlad Yasevich) [Orabug: 17371118] {CVE-2013-2206}
- sctp: deal with multiple COOKIE_ECHO chunks (Max Matveev) [Orabug: 17372121] {CVE-2013-2206}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:17.019-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:59.654-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.956-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:129096"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:128880"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:128675"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:129057"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:128990"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.6.el5uek" test_ref="oval:org.mitre.oval:tst:128764"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128525"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128826"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128937"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128182"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:128942"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.109.6.el6uek" test_ref="oval:org.mitre.oval:tst:129157"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27362" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0496 -- Oracle Linux 6 kernel security and bugfix  update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0496.html" ref_id="ELSA-2013-0496"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0190" ref_id="CVE-2013-0190"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0309" ref_id="CVE-2013-0309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0311" ref_id="CVE-2013-0311"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0310" ref_id="CVE-2013-0310"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4508" ref_id="CVE-2012-4508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4542" ref_id="CVE-2012-4542"/>
        <description>This update fixes the following security issues:

* A race condition was found in the way asynchronous I/O and fallocate()
interacted when using the ext4 file system. A local, unprivileged user
could use this flaw to expose random data from an extent whose data blocks
have not yet been written, and thus contain data from a deleted file.
(CVE-2012-4508, Important)

* A flaw was found in the way the vhost kernel module handled descriptors
that spanned multiple regions. A privileged guest user in a KVM guest could
use this flaw to crash the host or, potentially, escalate their privileges
on the host. (CVE-2013-0311, Important)

* It was found that the default SCSI command filter does not accommodate
commands that overlap across device classes. A privileged guest user could
potentially use this flaw to write arbitrary data to a LUN that is
passed-through as read-only. (CVE-2012-4542, Moderate)

* A flaw was found in the way the xen_failsafe_callback() function in the
Linux kernel handled the failed iret (interrupt return) instruction
notification from the Xen hypervisor. An unprivileged user in a 32-bit
para-virtualized guest could use this flaw to crash the guest.
(CVE-2013-0190, Moderate)

* A flaw was found in the way pmd_present() interacted with PROT_NONE
memory ranges when transparent hugepages were in use. A local, unprivileged
user could use this flaw to crash the system. (CVE-2013-0309, Moderate)

* A flaw was found in the way CIPSO (Common IP Security Option) IP options
were validated when set from user mode. A local user able to set CIPSO IP
options on the socket could use this flaw to crash the system.
(CVE-2013-0310, Moderate)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:47.727-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:59.091-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.648-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:51:20.843-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:51:20.843-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:129870"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:129801"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:129315"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:129718"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:130277"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:129932"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:129882"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:130287"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:129957"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27361" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0255 -- subversion security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0255.html" ref_id="ELSA-2014-0255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1968" ref_id="CVE-2013-1968"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2112" ref_id="CVE-2013-2112"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0032" ref_id="CVE-2014-0032"/>
        <description>[1.6.11-10]
- add security fixes for CVE-2013-1968, CVE-2013-2112, CVE-2014-0032</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:31.562-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:58.690-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.420-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128053"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128140"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128085"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128114"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128121"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:128128"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127818"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:128144"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:128000"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127851"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127854"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:128060"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127397"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127725"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:127910"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27360" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0321 -- cvs security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cvs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0321.html" ref_id="ELSA-2012-0321"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0804" ref_id="CVE-2012-0804"/>
        <description>[1.11.23-11.el6_2.1]
- Fix CVE-2012-0804 (Resolves: #784338)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:17.805-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:58.514-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.275-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:27:42.238-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:27:42.238-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cvs is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:132690"/>
            <criterion comment="cvs-inetd is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:132751"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="cvs is earlier than 0:1.11.23-11.el6_2.1" test_ref="oval:org.mitre.oval:tst:132511"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27359" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1452 -- vino security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1452.html" ref_id="ELSA-2013-1452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5745" ref_id="CVE-2013-5745"/>
        <description>[2.28.1-9]
- Reject clients in deferred auth state
  - Bug 1009228</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:23.084-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:58.346-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.177-05:00">ACCEPTED</status_change>
            <modified comment="duplicate" date="2015-02-11T09:24:36.440-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T09:24:36.440-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="vino is earlier than 0:2.13.5-10.el5_10" test_ref="oval:org.mitre.oval:tst:128765"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="vino is earlier than 0:2.28.1-9.el6_4" test_ref="oval:org.mitre.oval:tst:128835"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27358" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2585 -- Unbreakable Enterprise Kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2585.html" ref_id="ELSA-2013-2585"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6545" ref_id="CVE-2012-6545"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3231" ref_id="CVE-2013-3231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2164" ref_id="CVE-2013-2164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2234" ref_id="CVE-2013-2234"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343" ref_id="CVE-2013-0343"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4345" ref_id="CVE-2013-4345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1928" ref_id="CVE-2013-1928"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2888" ref_id="CVE-2013-2888"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2889" ref_id="CVE-2013-2889"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2892" ref_id="CVE-2013-2892"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4591" ref_id="CVE-2013-4591"/>
        <description>kernel-uek
[2.6.32-400.33.3uek]
- af_key: fix info leaks in notify messages (Mathias Krause) [Orabug: 17837974] {CVE-2013-2234}
- drivers/cdrom/cdrom.c: use kzalloc() for failing hardware (Jonathan Salwan) [Orabug: 17837971] {CVE-2013-2164}
- fs/compat_ioctl.c: VIDEO_SET_SPU_PALETTE missing error check (Kees Cook) [Orabug: 17837966] {CVE-2013-1928}
- Bluetooth: RFCOMM - Fix info leak in ioctl(RFCOMMGETDEVLIST) (Mathias Krause) [Orabug: 17837959] {CVE-2012-6545}
- Bluetooth: RFCOMM - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17838023] {CVE-2012-6545}
- llc: Fix missing msg_namelen update in llc_ui_recvmsg() (Mathias Krause) [Orabug: 17837945] {CVE-2013-3231}
- HID: pantherlord: validate output report details (Kees Cook) [Orabug: 17837942] {CVE-2013-2892}
- HID: zeroplus: validate output report details (Kees Cook) [Orabug: 17837936] {CVE-2013-2889}
- HID: provide a helper for validating hid reports (Kees Cook) [Orabug: 17837936] 
- NFSv4: Check for buffer length in __nfs4_get_acl_uncached (Sven Wegener) [Orabug: 17837931] {CVE-2013-4591}
- ansi_cprng: Fix off by one error in non-block size request (Neil Horman) [Orabug: 17837999] {CVE-2013-4345}
- HID: validate HID report id size (Kees Cook) [Orabug: 17837925] {CVE-2013-2888}
- ipv6: remove max_addresses check from ipv6_create_tempaddr (Hannes Frederic Sowa) [Orabug: 17837923] {CVE-2013-0343}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:35.000-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:57.868-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:36.014-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:128329 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:59.177-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:17.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127868"/>
            <criterion comment="mlnx_en-2.6.32-400.33.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127852"/>
            <criterion comment="ofa-2.6.32-400.33.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128329"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127951"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127730"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:128186"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127834"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:127667"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.3.el5uek" test_ref="oval:org.mitre.oval:tst:128421"/>
            <criterion comment="mlnx_en-2.6.32-400.33.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128213"/>
            <criterion comment="ofa-2.6.32-400.33.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128330"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128208"/>
            <criterion comment="mlnx_en-2.6.32-400.33.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128070"/>
            <criterion comment="ofa-2.6.32-400.33.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128490"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128390"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128195"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128283"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128233"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:127844"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.3.el6uek" test_ref="oval:org.mitre.oval:tst:128274"/>
            <criterion comment="mlnx_en-2.6.32-400.33.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127856"/>
            <criterion comment="ofa-2.6.32-400.33.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127816"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27357" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0771 -- curl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0771.html" ref_id="ELSA-2013-0771"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1944" ref_id="CVE-2013-1944"/>
        <description>[7.19.7-36]
- fix cookie tailmatching to prevent cross-domain leakage (CVE-2013-1944)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:50.317-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:57.676-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:35.905-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:10:46.807-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:10:46.807-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:129367"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:129254"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:129691"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:129515"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:129742"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27355" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0503 -- 389-ds-base security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0503.html" ref_id="ELSA-2013-0503"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4450" ref_id="CVE-2012-4450"/>
        <description>[1.2.11.15-11]
- Resolves: Bug 896256 - updating package touches configuration files</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:39.029-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:57.515-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:35.787-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:18:50.381-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:18:50.381-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-11.el6" test_ref="oval:org.mitre.oval:tst:129382"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-11.el6" test_ref="oval:org.mitre.oval:tst:130370"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-11.el6" test_ref="oval:org.mitre.oval:tst:130316"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27354" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0513 -- libxml2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0513.html" ref_id="ELSA-2014-0513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2877" ref_id="CVE-2013-2877"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0191" ref_id="CVE-2014-0191"/>
        <description>[2.7.6-14.0.1.el6_5.1]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[2-2.7.6-14.el6_5.1]
- Improve handling of xmlStopParser(CVE-2013-2877)
- Do not fetch external parameter entities (CVE-2014-0191)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:30.109-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:57.279-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:35.628-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:42:26.347-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:42:26.347-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libxml2 is earlier than 0:2.7.6-14.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127374"/>
          <criterion comment="libxml2-devel is earlier than 0:2.7.6-14.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127647"/>
          <criterion comment="libxml2-python is earlier than 0:2.7.6-14.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127572"/>
          <criterion comment="libxml2-static is earlier than 0:2.7.6-14.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127571"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27353" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0770 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0770.html" ref_id="ELSA-2013-0770"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2420" ref_id="CVE-2013-2420"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2422" ref_id="CVE-2013-2422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2429" ref_id="CVE-2013-2429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2431" ref_id="CVE-2013-2431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1537" ref_id="CVE-2013-1537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2419" ref_id="CVE-2013-2419"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2421" ref_id="CVE-2013-2421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2424" ref_id="CVE-2013-2424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2426" ref_id="CVE-2013-2426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2430" ref_id="CVE-2013-2430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0401" ref_id="CVE-2013-0401"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1518" ref_id="CVE-2013-1518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2383" ref_id="CVE-2013-2383"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1488" ref_id="CVE-2013-1488"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1558" ref_id="CVE-2013-1558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1569" ref_id="CVE-2013-1569"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2417" ref_id="CVE-2013-2417"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1557" ref_id="CVE-2013-1557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2384" ref_id="CVE-2013-2384"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2415" ref_id="CVE-2013-2415"/>
        <description>[1:1.6.0.0-1.61.1.11.11]
- added and applied (temporally) patch10   fixToFontSecurityFix.patch.
 - fixing regression in fonts introduced by one security patch.
- Resolves: rhbz#950386

[1:1.6.0.0-1.60.1.11.11]
- added and applied (temporally) one more patch to xalan/xerces privileges
 - patch9 jaxp-backport-factoryfinder.patch
- will be upstreamed
- Resolves: rhbz#950386

[1:1.6.0.0-1.59.1.11.11]
- Updated to icedtea6 1.11.11 - fixed xalan/xerxes privledges
- removed patch 8 -  removingOfAarch64.patch.patch - fixed upstream
- Resolves: rhbz#950386

[1:1.6.0.0-1.58.1.11.10]
- Updated to icedtea6 1.11.10
- rewritten java-1.6.0-openjdk-java-access-bridge-security.patch
- excluded aarch64.patch
  - by patch 8 -  removingOfAarch64.patch.patch
- Resolves: rhbz#950386</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:01.422-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:55.635-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:34.835-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:36:23.617-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:36:23.617-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129580"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128707"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129498"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129574"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.40.1.11.11.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129373"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129614"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129683"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129595"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129618"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:129706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27352" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3041 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3041.html" ref_id="ELSA-2014-3041"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1737" ref_id="CVE-2014-1737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1738" ref_id="CVE-2014-1738"/>
        <description>kernel-uek
[3.8.13-35.1.2.el6uek]
- floppy: don't write kernel-only members to FDRAWCMD ioctl output (Matthew Daley)  [Orabug: 19028443]  {CVE-2014-1738}
- floppy: ignore kernel-only members in FDRAWCMD ioctl input (Matthew Daley)  [Orabug: 19028436]  {CVE-2014-1737}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:20.348-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:55.509-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:34.735-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27352 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:04.759-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:16.958-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-35.1.2.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:127448"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-35.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:127407"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-35.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:127521"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-35.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:127180"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-35.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:127446"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-35.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:127445"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-35.1.2.el6uek" test_ref="oval:org.mitre.oval:tst:126878"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27350" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1475 -- postgresql and postgresql84 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1475.html" ref_id="ELSA-2013-1475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0255" ref_id="CVE-2013-0255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1900" ref_id="CVE-2013-1900"/>
        <description>[8.4.18-1]
- Update to PostgreSQL 8.4.18, for various fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-14.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-15.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-16.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-17.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-18.html
  including fixes for CVE-2013-0255, CVE-2013-1900 (#1017837)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:24.829-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:54.599-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:34.328-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:38:03.560-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:38:03.560-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128748"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128777"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128557"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128375"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128634"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128217"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128629"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128760"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128798"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128620"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128119"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:128316"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128723"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128726"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128528"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128650"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128735"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128785"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128350"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128535"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128684"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:128561"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27349" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0609 -- qemu-kvm security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0609.html" ref_id="ELSA-2013-0609"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6075" ref_id="CVE-2012-6075"/>
        <description>[qemu-kvm-0.12.1.2-2.355.el6_4.2]
- kvm-e1000-Discard-packets-that-are-too-long-if-SBP-and-L.patch [bz#910841]
- kvm-e1000-Discard-oversized-packets-based-on-SBP-LPE.patch [bz#910841]
- Resolves: bz#910841
  (CVE-2012-6075  qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [rhel-6.4.z])

[qemu-kvm-0.12.1.2-2.355.el6_4.1]
- kvm-Revert-e1000-no-need-auto-negotiation-if-link-was-do.patch [bz#907397]
- Resolves: bz#907397
  (Patch 'e1000: no need auto-negotiation if link was down' may break e1000 guest)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:04.374-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:54.433-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:34.254-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:28:46.486-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:28:46.486-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:129754"/>
          <criterion comment="qemu-guest-agent is earlier than 0:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:129993"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27348" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0449 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0449.html" ref_id="ELSA-2014-0449"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1518" ref_id="CVE-2014-1518"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1523" ref_id="CVE-2014-1523"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1524" ref_id="CVE-2014-1524"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1529" ref_id="CVE-2014-1529"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1530" ref_id="CVE-2014-1530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1531" ref_id="CVE-2014-1531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1532" ref_id="CVE-2014-1532"/>
        <description>[24.5.0-1.0.1]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[24.5.0-1]
- Update to 24.5.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:09.770-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:53.788-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:34.034-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:35:43.573-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:35:43.573-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127628"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127311"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27347" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3016 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3016.html" ref_id="ELSA-2014-3016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0101" ref_id="CVE-2014-0101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2523" ref_id="CVE-2014-2523"/>
        <description>kernel-uek
[2.6.32-400.34.4uek]
- netfilter: nf_conntrack_dccp: fix skb_header_pointer API usages (Daniel Borkmann)  [Orabug: 18462076]  {CVE-2014-2523}
- net: sctp: fix sctp_sf_do_5_1D_ce to verify if we/peer is AUTH capable (Daniel Borkmann)  [Orabug: 18461091]  {CVE-2014-0101}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:27.083-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:53.308-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:33.811-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127710 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:55.716-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:16.703-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127541"/>
            <criterion comment="mlnx_en-2.6.32-400.34.4.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126947"/>
            <criterion comment="ofa-2.6.32-400.34.4.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127802"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127380"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127772"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127484"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127191"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127799"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.4.el5uek" test_ref="oval:org.mitre.oval:tst:127728"/>
            <criterion comment="mlnx_en-2.6.32-400.34.4.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127705"/>
            <criterion comment="ofa-2.6.32-400.34.4.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127786"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127181"/>
            <criterion comment="mlnx_en-2.6.32-400.34.4.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127601"/>
            <criterion comment="ofa-2.6.32-400.34.4.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127595"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127841"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127795"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127683"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127862"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127798"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.4.el6uek" test_ref="oval:org.mitre.oval:tst:127775"/>
            <criterion comment="mlnx_en-2.6.32-400.34.4.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127719"/>
            <criterion comment="ofa-2.6.32-400.34.4.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127710"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27345" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0164 -- mysql security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0164.html" ref_id="ELSA-2014-0164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5908" ref_id="CVE-2013-5908"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0001" ref_id="CVE-2014-0001"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0386" ref_id="CVE-2014-0386"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0393" ref_id="CVE-2014-0393"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0401" ref_id="CVE-2014-0401"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0402" ref_id="CVE-2014-0402"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0412" ref_id="CVE-2014-0412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0437" ref_id="CVE-2014-0437"/>
        <description>[5.1.73-3]
- Fixes for CVE-2014-0001
  Resolves: #1055880

[5.1.73-2]
- Make mysqld init script more robust and ignore existing but
  non-being-used unix socket file
  Resolves: #1058719

[5.1.73-1]
- Update to MySQL 5.1.73, for various fixes described at
  http://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-73.html
  (CVE-2014-0412, CVE-2014-0437, CVE-2013-5908, CVE-2014-0393,
  CVE-2014-0386, CVE-2014-0401, CVE-2014-0402)
  Resolves: #1055880</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:13.680-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:52.436-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:33.375-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:57:38.246-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:57:38.246-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:128076"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:128125"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:128151"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:127190"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:127922"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:127289"/>
          <criterion comment="mysql-server is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:127290"/>
          <criterion comment="mysql-test is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:127640"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27343" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2589 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2589.html" ref_id="ELSA-2013-2589"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2141" ref_id="CVE-2013-2141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4470" ref_id="CVE-2013-4470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6367" ref_id="CVE-2013-6367"/>
        <description>kernel-uek
[2.6.32-400.33.4uek]
- kernel/signal.c: stop info leak via the tkill and the tgkill syscalls (Emese Revfy) [Orabug: 17951083] {CVE-2013-2141}
- ip_output: do skb ufo init for peeked non ufo skb as well (Jiri Pirko) [Orabug: 17951078] {CVE-2013-4470}
- KVM: x86: Fix potential divide by 0 in lapic (CVE-2013-6367) (Andy Honig) [Orabug: 17951073] {CVE-2013-6367}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:51.156-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:51.869-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:33.080-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35092 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:58.339-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:16.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127696"/>
            <criterion comment="mlnx_en-2.6.32-400.33.4.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128230"/>
            <criterion comment="ofa-2.6.32-400.33.4.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128117"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:128261"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127751"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:128285"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127991"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127825"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.4.el5uek" test_ref="oval:org.mitre.oval:tst:127783"/>
            <criterion comment="mlnx_en-2.6.32-400.33.4.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128082"/>
            <criterion comment="ofa-2.6.32-400.33.4.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128021"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128020"/>
            <criterion comment="mlnx_en-2.6.32-400.33.4.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127695"/>
            <criterion comment="ofa-2.6.32-400.33.4.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127762"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128214"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:127534"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128202"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128083"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:128280"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.33.4.el6uek" test_ref="oval:org.mitre.oval:tst:127938"/>
            <criterion comment="mlnx_en-2.6.32-400.33.4.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127376"/>
            <criterion comment="ofa-2.6.32-400.33.4.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128296"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27342" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0907 -- java-1.6.0-openjdk security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0907.html" ref_id="ELSA-2014-0907"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2490" ref_id="CVE-2014-2490"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4209" ref_id="CVE-2014-4209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4216" ref_id="CVE-2014-4216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4218" ref_id="CVE-2014-4218"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4219" ref_id="CVE-2014-4219"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4244" ref_id="CVE-2014-4244"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4252" ref_id="CVE-2014-4252"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4262" ref_id="CVE-2014-4262"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4263" ref_id="CVE-2014-4263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4266" ref_id="CVE-2014-4266"/>
        <description>[1:1.6.0.1-6.1.13.4]
- moved to  icedteaver 1.13.4
- moved to openjdkver b32 and openjdkdate 15_jul_2014
- added upstreamed patch patch9 rh1115580-unsyncHashMap.patch
- Resolves: rhbz#1115580
- Resolves: rhbz#1115867</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:18.130-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:50.855-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:32.717-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127230 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:45.204-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:32.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127304"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127132"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127303"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127175"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126834"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:127377"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:127355"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:126673"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:127228"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:127230"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127321"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127357"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127305"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127152"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:127244"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27341" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3048 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3048.html" ref_id="ELSA-2014-3048"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943" ref_id="CVE-2014-4943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4699" ref_id="CVE-2014-4699"/>
        <description>kernel-uek
[2.6.32-400.36.4uek]
- l2tp: fix an unprivileged user to kernel privilege escalation (Sasha Levin)  [Orabug: 19229529]  {CVE-2014-4943} {CVE-2014-4943}
- ptrace,x86: force IRET path after a ptrace_stop() (Tejun Heo)  [Orabug: 19230692]  {CVE-2014-4699}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:38.270-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:50.601-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:32.513-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:34671 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:57.171-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:16.104-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:126433"/>
            <criterion comment="mlnx_en-2.6.32-400.36.4.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127219"/>
            <criterion comment="ofa-2.6.32-400.36.4.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126524"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127419"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127263"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127501"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127331"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:126794"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.4.el5uek" test_ref="oval:org.mitre.oval:tst:127340"/>
            <criterion comment="mlnx_en-2.6.32-400.36.4.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127160"/>
            <criterion comment="ofa-2.6.32-400.36.4.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127523"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127119"/>
            <criterion comment="mlnx_en-2.6.32-400.36.4.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126965"/>
            <criterion comment="ofa-2.6.32-400.36.4.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127260"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127254"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127525"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127512"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:126565"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127072"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.4.el6uek" test_ref="oval:org.mitre.oval:tst:127193"/>
            <criterion comment="mlnx_en-2.6.32-400.36.4.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127245"/>
            <criterion comment="ofa-2.6.32-400.36.4.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126934"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27339" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0345 -- qemu-kvm security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0345.html" ref_id="ELSA-2011-0345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0011" ref_id="CVE-2011-0011"/>
        <description>[qemu-kvm-0.12.1.2-2.113.el6_0.8]
- kvm-Revert-blockdev-Fix-drive_del-not-to-crash-when-driv.patch [bz#677170]
- kvm-Revert-blockdev-check-dinfo-ptr-before-using-v2.patch [bz#677170]
- kvm-Revert-Implement-drive_del-to-decouple-block-removal.patch [bz#677170]
- kvm-Revert-block-Catch-attempt-to-attach-multiple-device.patch [bz#677170]
- kvm-Revert-qdev-Decouple-qdev_prop_drive-from-DriveInfo-.patch [bz#677170]
- kvm-Revert-blockdev-Clean-up-automatic-drive-deletion-v2.patch [bz#677170]
- kvm-Revert-blockdev-New-drive_get_by_blockdev-v2.patch [bz#677170]
- kvm-Revert-qdev-Don-t-leak-string-property-value-on-hot-.patch [bz#677170]
- kvm-Revert-ide-Split-non-qdev-code-off-ide_init2.patch [bz#677170]
- kvm-Revert-ide-Change-ide_init_drive-to-require-valid-di.patch [bz#677170]
- kvm-Revert-ide-Split-ide_init1-off-ide_init2-v2.patch [bz#677170]
- kvm-Revert-ide-Remove-redundant-IDEState-member-conf.patch [bz#677170]
- Related: bz#677170
  (drive_del command to let libvirt safely remove block device from guest)

[qemu-kvm-0.12.1.2-2.113.el6_0.7]
- kvm-ide-Remove-redundant-IDEState-member-conf.patch [bz#677170]
- kvm-ide-Split-ide_init1-off-ide_init2-v2.patch [bz#677170]
- kvm-ide-Change-ide_init_drive-to-require-valid-dinfo-arg.patch [bz#677170]
- kvm-ide-Split-non-qdev-code-off-ide_init2.patch [bz#677170]
- kvm-qdev-Don-t-leak-string-property-value-on-hot-unplug.patch [bz#677170]
- kvm-blockdev-New-drive_get_by_blockdev-v2.patch [bz#677170]
- kvm-blockdev-Clean-up-automatic-drive-deletion-v2.patch [bz#677170]
- kvm-qdev-Decouple-qdev_prop_drive-from-DriveInfo-v2.patch [bz#677170]
- kvm-block-Catch-attempt-to-attach-multiple-devices-to-a-.patch [bz#677170]
- kvm-Implement-drive_del-to-decouple-block-removal-from-d.patch [bz#677170]
- kvm-blockdev-check-dinfo-ptr-before-using-v2.patch [bz#677170]
- kvm-blockdev-Fix-drive_del-not-to-crash-when-drive-is-no.patch [bz#677170]
- kvm-Fix-CVE-2011-0011-qemu-kvm-Setting-VNC-password-to-e.patch [bz#668598]
- Resolves: bz#668598
  (CVE-2011-0011 qemu-kvm: Setting VNC password to empty string silently disables all authentication [rhel-6.0.z])
- Resolves: bz#677170
  (drive_del command to let libvirt safely remove block device from guest)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:42.442-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:50.085-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:32.104-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:50:12.779-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:50:12.779-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.113.el6_0.8" test_ref="oval:org.mitre.oval:tst:134049"/>
          <criterion comment="qemu-img is earlier than 0:0.12.1.2-2.113.el6_0.8" test_ref="oval:org.mitre.oval:tst:134171"/>
          <criterion comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.113.el6_0.8" test_ref="oval:org.mitre.oval:tst:134103"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27338" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2583 -- Unbreakable Enterprise Kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>dtrace-modules-3.8.13-16.2.2.el6uek-provider-headers</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2583.html" ref_id="ELSA-2013-2583"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343" ref_id="CVE-2013-0343"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4345" ref_id="CVE-2013-4345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2888" ref_id="CVE-2013-2888"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2889" ref_id="CVE-2013-2889"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2892" ref_id="CVE-2013-2892"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4387" ref_id="CVE-2013-4387"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4592" ref_id="CVE-2013-4592"/>
        <description>[3.8.13-16.2.2.el6uek]
- HID: pantherlord: validate output report details (Kees Cook) [Orabug: 17841973] {CVE-2013-2892}
- HID: zeroplus: validate output report details (Kees Cook) [Orabug: 17841968] {CVE-2013-2889}
- HID: provide a helper for validating hid reports (Kees Cook) [Orabug: 17841968] {CVE-2013-2889}
- KVM: Fix iommu map/unmap to handle memory slot moves (Alex Williamson) [Orabug: 17841960] {CVE-2013-4592}
- ansi_cprng: Fix off by one error in non-block size request (Jerry Snitselaar) [Orabug: 17837997] {CVE-2013-4345}
- HID: validate HID report id size (Kees Cook) [Orabug: 17841940] {CVE-2013-2888}
- ipv6: remove max_addresses check from ipv6_create_tempaddr (Hannes Frederic Sowa) [Orabug: 17841911] {CVE-2013-0343}
- ipv6: udp packets following an UFO enqueued packet need also be handled by UFO (Hannes Frederic Sowa) [Orabug: 17841928] {CVE-2013-4387}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:51.774-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:49.464-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:31.954-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35547 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:01.489-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:15.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-16.2.2.el6uek is earlier than 0:0.4.1-3.el6" test_ref="oval:org.mitre.oval:tst:128442"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-16.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:127897"/>
          <criterion comment="dtrace-modules-3.8.13-16.2.2.el6uek-headers is earlier than 0:0.4.1-3.el6" test_ref="oval:org.mitre.oval:tst:128078"/>
          <criterion comment="dtrace-modules-3.8.13-16.2.2.el6uek-provider-headers is earlier than 0:0.4.1-3.el6" test_ref="oval:org.mitre.oval:tst:128209"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-16.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:128164"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-16.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:128443"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-16.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:128071"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-16.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:128334"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-16.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:128389"/>
          <criterion comment="kernel-uek-headers is earlier than 0:3.8.13-16.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:128323"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27335" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0018 -- libxfont security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0018.html" ref_id="ELSA-2014-0018"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6462" ref_id="CVE-2013-6462"/>
        <description>[1.4.5-3]
- cve-2013-6462.patch: sscanf overflow (bug 1049684)
- sscanf-hardening.patch: Some other sscanf hardening fixes (1049684)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:30.896-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:48.318-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:31.217-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:13:30.905-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:13:30.905-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:127927"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:128067"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:128215"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:127999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27333" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0502 -- Core X11 clients security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-apps</product>
          <product>xorg-x11-server-utils</product>
          <product>xorg-x11-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0502.html" ref_id="ELSA-2013-0502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2504" ref_id="CVE-2011-2504"/>
        <description>xorg-x11-apps
[7.6-6]
- x11perf 1.5.4 (CVE-2011-2504)

[7.5-13]
- xinput 1.6.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:49.461-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:47.834-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:30.844-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:18:16.160-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:18:16.160-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xorg-x11-apps is earlier than 0:7.6-6.el6" test_ref="oval:org.mitre.oval:tst:130171"/>
          <criterion comment="xorg-x11-server-utils is earlier than 0:7.5-13.el6" test_ref="oval:org.mitre.oval:tst:129794"/>
          <criterion comment="xorg-x11-utils is earlier than 0:7.5-6.el6" test_ref="oval:org.mitre.oval:tst:129914"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27330" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1009 -- java-1.7.0-openjdk security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1009.html" ref_id="ELSA-2012-1009"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1711" ref_id="CVE-2012-1711"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1713" ref_id="CVE-2012-1713"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1716" ref_id="CVE-2012-1716"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1717" ref_id="CVE-2012-1717"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1718" ref_id="CVE-2012-1718"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1719" ref_id="CVE-2012-1719"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1723" ref_id="CVE-2012-1723"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1724" ref_id="CVE-2012-1724"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1725" ref_id="CVE-2012-1725"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1726" ref_id="CVE-2012-1726"/>
        <description>[1.7.0.5-2.2.1.0.1.el6]
- Modify DISTRO_NAME for Oracle

[1.7.0.5-2.2.1.el6]
- Updated priority to be > 17000 and to depend on buildver variable
- Variable buildver increased to 5 as it should be
- Resolves: rhbz#828759

[1.7.0.3-2.2.1.el6]
- Used newly prepared tarball with security fixes
- Bump to icedtea7-forest-2.2.1
- _mandir/man1/jcmd-name.1 added to alternatives
- Updated rhino.patch
- Updated java-1.7.0-openjdk-java-access-bridge-security.patch
- Modified partially upstreamed patch302 - systemtap.patch
- Temporarly disabled patch102 - java-1.7.0-openjdk-size_t.patch
- Removed already upstreamed patches 104,108,109,301,110:
  - java-1.7.0-openjdk-arm-ftbfs.patch
  - java-1.7.0-openjdk-system-zlib.patch
  - java-1.7.0-openjdk-remove-mimpure-opt.patch
  - systemtap-alloc-size-workaround.patch
  - java-1.7.0-fix-gio-detection.patch
- Access gnome bridge jar forced to be 644
- Added patch303 - java-1.7.0-openjdk-jstack.patch which resolved RH804632 for openjdk6
- Resolves: rhbz#828759</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:36.604-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:44.969-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:29.595-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:06:32.317-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:06:32.317-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131767"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131104"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131265"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131347"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.5-2.2.1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27329" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0918 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0918.html" ref_id="ELSA-2014-0918"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1547" ref_id="CVE-2014-1547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1555" ref_id="CVE-2014-1555"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1556" ref_id="CVE-2014-1556"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1557" ref_id="CVE-2014-1557"/>
        <description>[24.7.0-1.0.1.el6_5]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[24.7.0-1]
- Update to 24.7.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:09.334-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:44.534-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:29.490-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127343"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:126814"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27326" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0741 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0741.html" ref_id="ELSA-2014-0741"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1533" ref_id="CVE-2014-1533"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1538" ref_id="CVE-2014-1538"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1541" ref_id="CVE-2014-1541"/>
        <description>[24.6.0-1.0.1.el6_5]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one

[24.6.0-1]
- Update to 24.6.0 ESR

[24.5.0-2]
- Disabled unused patches</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:15.356-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:42.175-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:29.091-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:46:51.933-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:46:51.933-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127366"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127491"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27324" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1090 -- ruby security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1090.html" ref_id="ELSA-2013-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4073" ref_id="CVE-2013-4073"/>
        <description>[1.8.7.352-12]
- Fix regression introduced by CVE-2013-4073
  https://bugs.ruby-lang.org/issues/8575
  * ruby-2.0.0-p255-Fix-SSL-client-connection-crash-for-SAN-marked-critical.patch
  - Related: rhbz#979300

[1.8.7.352-11]
- hostname check bypassing vulnerability in SSL client.
  * ruby-1.8.7-p374-CVE-2013-4073-fix-hostname-verification.patch
  - Resolves: rhbz#979300</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:32.370-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:41.484-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:28.822-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:55:54.506-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:55:54.506-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ruby is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129100"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:128814"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129008"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:128508"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129228"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:128710"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129031"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129270"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:129191"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ruby is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129149"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129189"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129251"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129175"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129205"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129091"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129226"/>
            <criterion comment="ruby-static is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:129128"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:128591"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27322" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0211 -- postgresql84 and postgresql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0211.html" ref_id="ELSA-2014-0211"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0060" ref_id="CVE-2014-0060"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0061" ref_id="CVE-2014-0061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0062" ref_id="CVE-2014-0062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0063" ref_id="CVE-2014-0063"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0064" ref_id="CVE-2014-0064"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0065" ref_id="CVE-2014-0065"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0066" ref_id="CVE-2014-0066"/>
        <description>[8.4.20-1]
- Update to PostgreSQL 8.4.20 (#1065843) for fixes described at
  http://www.postgresql.org/docs/8.4/static/release-8-4-19.html
  http://www.postgresql.org/docs/8.4/static/release-8-4-20.html</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:14.451-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:40.530-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:28.242-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:19:53.793-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:19:53.793-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127860"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127909"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127998"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127827"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127156"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127426"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127779"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:128087"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:128007"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:128124"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127864"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:127988"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127916"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:128015"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:128123"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127453"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:128047"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127952"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127680"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127840"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127723"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:127866"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27319" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3009 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3009.html" ref_id="ELSA-2014-3009"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2929" ref_id="CVE-2013-2929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263" ref_id="CVE-2013-7263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7265" ref_id="CVE-2013-7265"/>
        <description>[2.6.39-400.214.3]
- inet: fix addr_len/msg->msg_namelen assignment in recv_error and rxpmtu functions (Hannes Frederic Sowa)  [18247289]  {CVE-2013-7263} {CVE-2013-7265}

[2.6.39-400.214.2]
- inet: prevent leakage of uninitialized memory to user in recv syscalls (Hannes Frederic Sowa)  [18238382]  {CVE-2013-7263} {CVE-2013-7265}
- exec/ptrace: fix get_dumpable() incorrect tests (Kees Cook)  [18238353]  {CVE-2013-2929}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:28.577-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:39.355-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:27.719-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:128112"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:127403"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:127497"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:127777"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:128120"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.3.el5uek" test_ref="oval:org.mitre.oval:tst:127746"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127774"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:128108"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127697"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127932"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127592"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.3.el6uek" test_ref="oval:org.mitre.oval:tst:127473"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27318" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3021 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3021.html" ref_id="ELSA-2014-3021"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0077" ref_id="CVE-2014-0077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6383" ref_id="CVE-2013-6383"/>
        <description>[3.8.13-26.2.4.el6uek]
- aacraid: missing capable() check in compat ioctl (Dan Carpenter)  [Orabug: 18721961]  {CVE-2013-6383}
- vhost: fix total length when packets are too short (Michael S. Tsirkin)  [Orabug: 18721976]  {CVE-2014-0077}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:41.598-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:39.134-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:27.557-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127309 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:56.649-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:14.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-26.2.4.el6uek is earlier than 0:0.4.2-3.el6" test_ref="oval:org.mitre.oval:tst:127309"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-26.2.4.el6uek" test_ref="oval:org.mitre.oval:tst:127554"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-26.2.4.el6uek" test_ref="oval:org.mitre.oval:tst:127502"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-26.2.4.el6uek" test_ref="oval:org.mitre.oval:tst:127265"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-26.2.4.el6uek" test_ref="oval:org.mitre.oval:tst:127551"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-26.2.4.el6uek" test_ref="oval:org.mitre.oval:tst:127518"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-26.2.4.el6uek" test_ref="oval:org.mitre.oval:tst:127442"/>
          <criterion comment="kernel-uek-headers is earlier than 0:3.8.13-26.2.4.el6uek" test_ref="oval:org.mitre.oval:tst:127593"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27317" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1543 -- samba4 security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1543.html" ref_id="ELSA-2013-1543"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124" ref_id="CVE-2013-4124"/>
        <description>[4.0.0-58.rc4]

- Fix winbind lsat reconnection code, avoids ntlmv2-only session setup problems

- resolves: #949993



[4.0.0-57.rc4]

- resolves: #984809 - CVE-2013-4124: DoS via integer overflow when reading

                      an EA list



[4.0.0-56.rc4]

- Fix libwbclient.so.0 symlink.

- resolves: #882338

- Fix correct linking of libreplace with cmdline-credentials.

- resolves: #911264</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:20.782-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:38.938-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:27.422-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba4 is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128477"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128666"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128386"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128671"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128491"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128670"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128613"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128483"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128479"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128617"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128338"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128689"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128600"/>
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:128690"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27316" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3037 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>dtrace-modules-headers</product>
          <product>dtrace-modules-provider-headers</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3037.html" ref_id="ELSA-2014-3037"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3153" ref_id="CVE-2014-3153"/>
        <description>kernel-uek
[3.8.13-35.1.1.el6uek]
- futex: Make lookup_pi_state more robust (Thomas Gleixner)  [Orabug: 18918552]  {CVE-2014-3153}
- futex: Always cleanup owner tid in unlock_pi (Thomas Gleixner)  [Orabug: 18918552]  {CVE-2014-3153}
- futex: Validate atomic acquisition in futex_lock_pi_atomic() (Thomas Gleixner)  [Orabug: 18918552]  {CVE-2014-3153}
- futex: Forbid uaddr == uaddr2 in futex_requeue(..., requeue_pi=1) (Thomas Gleixner)  [Orabug: 18918552]  {CVE-2014-3153} {CVE-2014-3153}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:30.529-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:38.715-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:27.240-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27316 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:04.975-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:14.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-35.1.1.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:127481"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-35.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:127359"/>
          <criterion comment="dtrace-modules-headers is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:127635"/>
          <criterion comment="dtrace-modules-provider-headers is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:127547"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-35.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:127610"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-35.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:127565"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-35.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:127475"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-35.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:127533"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-35.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:127637"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27315" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0391 -- libvirt security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0391.html" ref_id="ELSA-2011-0391"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1146" ref_id="CVE-2011-1146"/>
        <description>[0.8.1-27.0.1.el6_0.5]
- Replace docs/et.png in tarball with blank image

[0.8.1-27.el6_0.5]
- Properly report error in virConnectDomainXMLToNative (CVE-2011-1146)

[0.8.1-27.el6_0.4]
- Add missing checks for read-only connections (CVE-2011-1146)

[0.8.1-27.el6_0.3]
- Remove patches not suitable for proper Z-stream:
    - Export host information through SMBIOS to guests (rhbz#652678)
    - Support forcing a CDROM eject (rhbz#658147)
- Plug several memory leaks (rhbz#672549)
- Avoid memory overhead of matchpathcon (rhbz#672554)
- Do not start libvirt-guests if that service is off (rhbz#668694)

[0.8.1-27.el6_0.2]
- spec file cleanups (rhbz#662045)
- Fix deadlock on concurrent multiple bidirectional migration (rhbz#662043)
- Fix off-by-one error in clock-variable (rhbz#662046)
- Export host information through SMBIOS to guests (rhbz#652678)
- Ensure device is deleted from guest after unplug (rhbz#662041)
- Distinguish between QEMU domain shutdown and crash (rhbz#662042)

[0.8.1-27.el6_0.1]
- Fix JSON migrate_set_downtime command (rhbz#658143)
- Make SASL work over UNIX domain sockets (rhbz#658144)
- Let qemu group look below /var/lib/libvirt/qemu/ (rhbz#656972)
- Fix save/restore on root_squashed NFS (rhbz#656355)
- Fix race on multiple migration (rhbz#658141)
- Export host information through SMBIOS to guests (rhbz#652678)
- Support forcing a CDROM eject (rhbz#658147)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:54">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:02:09.874-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:38.515-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:27.092-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:46:13.114-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:46:13.114-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvirt is earlier than 0:0.8.2-15.0.1.el5_6.3" test_ref="oval:org.mitre.oval:tst:133946"/>
            <criterion comment="libvirt-devel is earlier than 0:0.8.2-15.0.1.el5_6.3" test_ref="oval:org.mitre.oval:tst:134187"/>
            <criterion comment="libvirt-python is earlier than 0:0.8.2-15.0.1.el5_6.3" test_ref="oval:org.mitre.oval:tst:134162"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvirt is earlier than 0:0.8.1-27.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134189"/>
            <criterion comment="libvirt-client is earlier than 0:0.8.1-27.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133953"/>
            <criterion comment="libvirt-devel is earlier than 0:0.8.1-27.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133544"/>
            <criterion comment="libvirt-python is earlier than 0:0.8.1-27.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133863"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27310" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-1416 -- kdelibs security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1416.html" ref_id="ELSA-2012-1416"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4512" ref_id="CVE-2012-4512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4513" ref_id="CVE-2012-4513"/>
        <description>[6:4.3.4-14.2]
- fix multilib conflict

[6:4.3.4-14.1]
- Resolves: bz#866228, CVE-2012-4512 CVE-2012-4513</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:36.657-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:36.440-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:26.113-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kdelibs is earlier than 0:4.3.4-14.el6_3.2" test_ref="oval:org.mitre.oval:tst:130391"/>
          <criterion comment="kdelibs-apidocs is earlier than 0:4.3.4-14.el6_3.2" test_ref="oval:org.mitre.oval:tst:130894"/>
          <criterion comment="kdelibs-common is earlier than 0:4.3.4-14.el6_3.2" test_ref="oval:org.mitre.oval:tst:130430"/>
          <criterion comment="kdelibs-devel is earlier than 0:4.3.4-14.el6_3.2" test_ref="oval:org.mitre.oval:tst:130768"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27309" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0126 -- openldap security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0126.html" ref_id="ELSA-2014-0126"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4449" ref_id="CVE-2013-4449"/>
        <description>[2.4.23-34.1]
- fix: segfault on certain queries with rwm overlay (#1058250)

[2.4.23-34]
- fix: deadlock during SSL_ForceHandshake (#996373)
  + revert nss-handshake-threadsafe.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:46.716-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:36.242-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:25.948-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:27:28.731-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:27:28.731-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openldap is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:128190"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:127208"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:127767"/>
          <criterion comment="openldap-servers is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:128101"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:127855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27308" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0744 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0744.html" ref_id="ELSA-2013-0744"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6546" ref_id="CVE-2012-6546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0349" ref_id="CVE-2013-0349"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0913" ref_id="CVE-2013-0913"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6547" ref_id="CVE-2012-6547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1796" ref_id="CVE-2013-1796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1798" ref_id="CVE-2013-1798"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1773" ref_id="CVE-2013-1773"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1792" ref_id="CVE-2013-1792"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1797" ref_id="CVE-2013-1797"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1827" ref_id="CVE-2013-1827"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1774" ref_id="CVE-2013-1774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6537" ref_id="CVE-2012-6537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1767" ref_id="CVE-2013-1767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1826" ref_id="CVE-2013-1826"/>
        <description>[2.6.32-358.6.1]
- [virt] kvm: accept unaligned MSR_KVM_SYSTEM_TIME writes (Petr Matousek) [917020 917021] {CVE-2013-1796}
- [char] tty: hold lock across tty buffer finding and buffer filling (Prarit Bhargava) [928686 901780]
- [net] tcp: fix for zero packets_in_flight was too broad (Thomas Graf) [927309 920794]
- [net] tcp: frto should not set snd_cwnd to 0 (Thomas Graf) [927309 920794]
- [net] tcp: fix an infinite loop in tcp_slow_start() (Thomas Graf) [927309 920794]
- [net] tcp: fix ABC in tcp_slow_start() (Thomas Graf) [927309 920794]
- [netdrv] ehea: avoid accessing a NULL vgrp (Steve Best) [921535 911359]
- [net] sunrpc: Get rid of the redundant xprt->shutdown bit field (J. Bruce Fields) [915579 893584]
- [virt] kvm: do not #GP on unaligned MSR_KVM_SYSTEM_TIME write (Gleb Natapov) [917020 917021] {CVE-2013-1796}
- [drm] i915: bounds check execbuffer relocation count (Nikola Pajkovsky) [920523 920525] {CVE-2013-0913}
- [x86] irq: add quirk for broken interrupt remapping on 55XX chipsets (Neil Horman) [911267 887006]
- [kvm] Convert MSR_KVM_SYSTEM_TIME to use gfn_to_hva_cache functions (Gleb Natapov) [917024 917025] {CVE-2013-1797}
- [kvm] Fix for buffer overflow in handling of MSR_KVM_SYSTEM_TIME (Gleb Natapov) [917020 917021] {CVE-2013-1796}
- [kvm] Fix bounds checking in ioapic indirect register reads (Gleb Natapov) [917030 917032] {CVE-2013-1798}
- [kvm] x86: release kvmclock page on reset (Gleb Natapov) [917024 917025] {CVE-2013-1797}
- [security] keys: Fix race with concurrent install_user_keyrings() (David Howells) [916681 913258] {CVE-2013-1792}
- [virt] hv_balloon: Make adjustments to the pressure report (Jason Wang) [909156 902232]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:43.369-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:35.118-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:25.442-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:38:00.394-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:38:00.394-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:129646"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:129666"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:128966"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:129493"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:129185"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:128939"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:129747"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:129017"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:129183"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27306" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0304 -- mutt security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mutt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0304.html" ref_id="ELSA-2014-0304"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0467" ref_id="CVE-2014-0467"/>
        <description>[5:1.5.20-4.20091214hg736b6a]
- Resolves: #1075872 (CVE-2014-0467, heap-based buffer overflow when parsing
  certain headers)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:16.559-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:34.803-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:25.203-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27306 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:22.134-05:00">INTERIM</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:16:36.059-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:16:36.059-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="mutt is earlier than 5:1.5.20-4.20091214hg736b6a.el6_5" test_ref="oval:org.mitre.oval:tst:127891"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27305" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1500 -- gc security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1500.html" ref_id="ELSA-2013-1500"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2673" ref_id="CVE-2012-2673"/>
        <description>[7.1-12]
- Fix host triplets on x86 (#1014273)
- Related: CVE-2012-2673

[7.1-11]
- Add sanity checking for calloc/malloc calls
- Resolves: CVE-2012-2673</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:02.738-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:34.604-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:25.110-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T10:58:16.135-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T10:58:16.135-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gc is earlier than 0:7.1-12.el6_4" test_ref="oval:org.mitre.oval:tst:128509"/>
          <criterion comment="gc-devel is earlier than 0:7.1-12.el6_4" test_ref="oval:org.mitre.oval:tst:128646"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27304" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2546 -- Unbreakable Enterprise Kernel security and bug fix  update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2546.html" ref_id="ELSA-2013-2546"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2164" ref_id="CVE-2013-2164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2234" ref_id="CVE-2013-2234"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6549" ref_id="CVE-2012-6549"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1772" ref_id="CVE-2013-1772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2140" ref_id="CVE-2013-2140"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3076" ref_id="CVE-2013-3076"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4163" ref_id="CVE-2013-4163"/>
        <description>[2.6.39-400.209.1]

- Revert 'stop mig handler when lockres in progress ,and return -EAGAIN' (Srinivas Eeda) [Orabug: 16924802] 

- ocfs2/dlm: Fix list traversal in dlm_process_recovery_data (Srinivas Eeda) [Orabug: 17432400] 

- ocfs2/dlm: ocfs2 dlm umount skip migrating lockres (Srinivas Eeda) [Orabug: 16859627]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:18.125-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:33.839-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:24.719-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128774"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128883"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128743"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:129033"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128813"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.209.1.el5uek" test_ref="oval:org.mitre.oval:tst:128909"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:129117"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:129120"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:128851"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:128916"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:128545"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.209.1.el6uek" test_ref="oval:org.mitre.oval:tst:129034"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27302" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1654 -- rsyslog7 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>rsyslog7</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1654.html" ref_id="ELSA-2014-1654"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3634" ref_id="CVE-2014-3634"/>
        <description>[7.4.10-3]
        - fix CVE-2014-3634
          resolves: #1149150</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:20.074-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:33.361-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:24.274-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="rsyslog7 is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:126670"/>
          <criterion comment="rsyslog7-elasticsearch is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:126458"/>
          <criterion comment="rsyslog7-gnutls is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:126627"/>
          <criterion comment="rsyslog7-gssapi is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:126572"/>
          <criterion comment="rsyslog7-mysql is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:126602"/>
          <criterion comment="rsyslog7-pgsql is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:126405"/>
          <criterion comment="rsyslog7-relp is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:126293"/>
          <criterion comment="rsyslog7-snmp is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:126265"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27301" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1131 -- krb5 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1131.html" ref_id="ELSA-2012-1131"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1013" ref_id="CVE-2012-1013"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1015" ref_id="CVE-2012-1015"/>
        <description>[1.9-33.2]
- pull up the patch to correct a possible NULL pointer dereference in
  kadmind (CVE-2012-1013, #827517)

[1.9-33.1]
- add candidate patch from upstream to fix freeing uninitialized pointer in
  the KDC (MITKRB5-SA-2012-001, CVE-2012-1015, #839859)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:15.071-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:33.092-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:24.140-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:16:13.289-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:16:13.289-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:131487"/>
          <criterion comment="krb5-devel is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:131459"/>
          <criterion comment="krb5-libs is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:131369"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:131420"/>
          <criterion comment="krb5-server is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:131362"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:131400"/>
          <criterion comment="krb5-workstation is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:131311"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27300" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1676 -- wireshark security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1676.html" ref_id="ELSA-2014-1676"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6421" ref_id="CVE-2014-6421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6422" ref_id="CVE-2014-6422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6423" ref_id="CVE-2014-6423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6424" ref_id="CVE-2014-6424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6425" ref_id="CVE-2014-6425"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6426" ref_id="CVE-2014-6426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6427" ref_id="CVE-2014-6427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6428" ref_id="CVE-2014-6428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6429" ref_id="CVE-2014-6429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6430" ref_id="CVE-2014-6430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6431" ref_id="CVE-2014-6431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6432" ref_id="CVE-2014-6432"/>
        <description>[1.10.3-12.0.1.el7]
        - Add oracle-ocfs2-network.patch to allow disassembly of OCFS2 interconnect</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:36.045-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:32.130-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:23.761-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.8.10-8.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126438"/>
            <criterion comment="wireshark-devel is earlier than 0:1.8.10-8.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126016"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.8.10-8.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126372"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.10.3-12.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126492"/>
            <criterion comment="wireshark-devel is earlier than 0:1.10.3-12.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126352"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.10.3-12.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126701"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27299" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0737 -- subversion security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0737.html" ref_id="ELSA-2013-0737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1849" ref_id="CVE-2013-1849"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1845" ref_id="CVE-2013-1845"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1847" ref_id="CVE-2013-1847"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1846" ref_id="CVE-2013-1846"/>
        <description>[1.6.11-9]
- add security fixes for CVE-2013-1846, CVE-2013-1847, CVE-2013-1849 (#947372)

[1.6.11-8]
- add security fix for CVE-2013-1845 (#947372)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:54.682-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:31.684-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:23.397-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:46:29.702-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:46:29.702-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129803"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129797"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:128871"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129734"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129411"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:129589"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="subversion is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129640"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129759"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129804"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129539"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129629"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:128824"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129750"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129784"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:129681"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27298" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3068 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3068.html" ref_id="ELSA-2014-3068"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4667" ref_id="CVE-2014-4667"/>
        <description>[2.6.39-400.215.7]
- sctp: Fix sk_ack_backlog wrap-around problem (Xufeng Zhang)  [Orabug: 19404245]  {CVE-2014-4667}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:20.989-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:31.468-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:23.253-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126861"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126994"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126826"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126780"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:126217"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.7.el5uek" test_ref="oval:org.mitre.oval:tst:127007"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126561"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126979"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:127025"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126427"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126820"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.7.el6uek" test_ref="oval:org.mitre.oval:tst:126288"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27293" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0865 -- tomcat6 security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0865.html" ref_id="ELSA-2014-0865"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0075" ref_id="CVE-2014-0075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0096" ref_id="CVE-2014-0096"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0099" ref_id="CVE-2014-0099"/>
        <description>[0:6.0.24-72]
- Related: CVE-2014-0075 - rebuild to generate javadoc
- correctly. previous build generated 0-length javadoc

[0:6.0.24-69]
- Related: CVE-2014-0075 incomplete

[0:6.0.24-68]
- Related: CVE-2013-4322. arches needs to be specified
- as in arches noarch, so docs/webapps will produce
- full files. building for ppc will generate empty
- javadoc.

[0:6.0.24-67]
- Related: CVE-2014-0050
- Related: CVE-2013-4322

[0:6.0.24-66]
- Resolves: CVE-2014-0099
- Resolves: CVE-2014-0096
- Resolves: CVE-2014-0075

[0:6.0.24-65]
- Related: CVE-2014-0050 copy paste error</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:27.684-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:30.039-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:22.381-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:127444"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:127367"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:127014"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:127449"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:127258"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:127141"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:127005"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:127368"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:127494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27292" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0983 -- curl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0983.html" ref_id="ELSA-2013-0983"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2174" ref_id="CVE-2013-2174"/>
        <description>[7.19.7-37]
- fix heap-based buffer overflow in curl_easy_unescape() (CVE-2013-2174)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:19.267-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:29.749-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:22.263-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:03:31.018-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:03:31.018-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:129420"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:129395"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:129426"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:128712"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:128683"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27291" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0957 -- java-1.7.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0957.html" ref_id="ELSA-2013-0957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1500" ref_id="CVE-2013-1500"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1571" ref_id="CVE-2013-1571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2407" ref_id="CVE-2013-2407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2412" ref_id="CVE-2013-2412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2443" ref_id="CVE-2013-2443"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2444" ref_id="CVE-2013-2444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2445" ref_id="CVE-2013-2445"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2446" ref_id="CVE-2013-2446"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2447" ref_id="CVE-2013-2447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2448" ref_id="CVE-2013-2448"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2449" ref_id="CVE-2013-2449"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2450" ref_id="CVE-2013-2450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2452" ref_id="CVE-2013-2452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2453" ref_id="CVE-2013-2453"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2454" ref_id="CVE-2013-2454"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2455" ref_id="CVE-2013-2455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2456" ref_id="CVE-2013-2456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2457" ref_id="CVE-2013-2457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2458" ref_id="CVE-2013-2458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2459" ref_id="CVE-2013-2459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2460" ref_id="CVE-2013-2460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2461" ref_id="CVE-2013-2461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2463" ref_id="CVE-2013-2463"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2465" ref_id="CVE-2013-2465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2469" ref_id="CVE-2013-2469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2470" ref_id="CVE-2013-2470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2471" ref_id="CVE-2013-2471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2472" ref_id="CVE-2013-2472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2473" ref_id="CVE-2013-2473"/>
        <description>[1.7.0.25-2.3.10.3.0.1.el6_4]
- Update DISTRO_NAME in specfile

[1.7.0.25-2.3.10.3.el6]
- removed upstreamed patch1000 MBeanFix.patch
- updated to newer IcedTea7-forest 2.3.10 with 8010118 fix
- Resolves: rhbz#973119

[1.7.0.25-2.3.10.2.el6]
- added patch1000 MBeanFix.patch to fix regressions caused by security patches
- Resolves: rhbz#973119

[1.7.0.25-2.3.10.1.el6]
- build bumped to 25
- Resolves: rhbz#973119

[1.7.0.19-2.3.10.0.el6]
- Updated to latest IcedTea7-forest 2.3.10
- patch 107 renamed to 500 for cosmetic purposes
- improved handling of patch111 - nss-config-2.patch
- removed patch 117, java-1.7.0-openjdk-nss-multiplePKCS11libraryInitialisationNnonCritical.patch
  duplicated with patch 108 (java-1.7.0-openjdk-nss-icedtea-e9c857dcb964)
- Added client/server directories so they can be owned
- Added fix for RH857717, owned /etc/.java/ and /etc/.java/.systemPrefs
- Resolves: rhbz#973119</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:17.475-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:26.584-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:21.232-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:42:13.324-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:42:13.324-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.25-2.3.10.3.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129222"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.25-2.3.10.3.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129432"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.25-2.3.10.3.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128938"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.25-2.3.10.3.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129239"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.25-2.3.10.3.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27290" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2025 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2025.html" ref_id="ELSA-2012-2025"/>
        <description>[2.6.39-200.29.2]

- epoll: clear the tfile_check_list on -ELOOP (Joe Jin) {CVE-2012-3375}

- Don't limit non-nested epoll paths (Jason Baron)

- epoll: kabi fixups for epoll limit wakeup paths (Joe Jin) {CVE-2011-1083}

- epoll: limit paths (Jason Baron)  {CVE-2011-1083}

- cred: copy_process() should clear child->replacement_session_keyring (Oleg

  Nesterov)  {CVE-2012-2745}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:09.723-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:26.406-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:21.062-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131646"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131614"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131645"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131257"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131394"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.29.2.el5uek" test_ref="oval:org.mitre.oval:tst:131533"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131435"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131538"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131636"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:130896"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131564"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.29.2.el6uek" test_ref="oval:org.mitre.oval:tst:131633"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27289" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1436 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1436.html" ref_id="ELSA-2013-1436"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4162" ref_id="CVE-2013-4162"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4299" ref_id="CVE-2013-4299"/>
        <description>[2.6.32-358.23.2]
- [md] dm-snapshot: fix data corruption (Mikulas Patocka) [1004252 1004233] {CVE-2013-4299}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:27.428-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:26.027-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:20.875-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:48:13.816-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:48:13.816-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:128469"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:129050"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:128979"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:128744"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:129040"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:128784"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:128580"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:128602"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:128894"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27287" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0747 -- python-jinja2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python-jinja2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0747.html" ref_id="ELSA-2014-0747"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1402" ref_id="CVE-2014-1402"/>
        <description>[2.2.1-2]
- Fix CVE-2014-1402
Resolves: rhbz#1102889</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:21.840-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:25.574-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:20.514-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:49:55.558-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:49:55.558-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="python-jinja2 is earlier than 0:2.2.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:127256"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27286" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0132 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0132.html" ref_id="ELSA-2014-0132"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1477" ref_id="CVE-2014-1477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1479" ref_id="CVE-2014-1479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1481" ref_id="CVE-2014-1481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1482" ref_id="CVE-2014-1482"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1486" ref_id="CVE-2014-1486"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1487" ref_id="CVE-2014-1487"/>
        <description>[24.3.0-2.0.1.el6_5]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one
- Build with nspr-devel >= 4.10.0 to fix build failure

[24.3.0-2]
- Update to 24.3.0 ESR Build 2

[24.3.0-1]
- Update to 24.3.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:41.473-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:24.846-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:20.238-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:43:06.824-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:43:06.824-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128097"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27285" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0310 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0310.html" ref_id="ELSA-2014-0310"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1493" ref_id="CVE-2014-1493"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1497" ref_id="CVE-2014-1497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1505" ref_id="CVE-2014-1505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1508" ref_id="CVE-2014-1508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1509" ref_id="CVE-2014-1509"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1510" ref_id="CVE-2014-1510"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1511" ref_id="CVE-2014-1511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1512" ref_id="CVE-2014-1512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1513" ref_id="CVE-2014-1513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1514" ref_id="CVE-2014-1514"/>
        <description>[24.4.0-1.0.1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one
- Build with nspr-devel >= 4.10.0 to fix build failure

[24.4.0-1]
- Update to 24.4.0 ESR

[24.3.0-4]
- Fixed rhbz#1070467 - Enable Add Ons by default in Firefox

[24.3.0-3]
- Fixed rhbz#1054832 - Firefox does not support Camellia cipher</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:11.981-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:23.732-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:19.884-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:20:25.022-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:20:25.022-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128031"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127672"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27284" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0139 -- pidgin security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0139.html" ref_id="ELSA-2014-0139"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6152" ref_id="CVE-2012-6152"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6477" ref_id="CVE-2013-6477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6478" ref_id="CVE-2013-6478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6479" ref_id="CVE-2013-6479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6481" ref_id="CVE-2013-6481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6482" ref_id="CVE-2013-6482"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6483" ref_id="CVE-2013-6483"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6484" ref_id="CVE-2013-6484"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6485" ref_id="CVE-2013-6485"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6487" ref_id="CVE-2013-6487"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6489" ref_id="CVE-2013-6489"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6490" ref_id="CVE-2013-6490"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0020" ref_id="CVE-2014-0020"/>
        <description>[2.7.9-27.el6]
- Fix regression in CVE-2013-6483.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:21.195-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:22.292-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:19.279-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:03:24.626-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:03:24.626-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pidgin is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:127699"/>
          <criterion comment="finch is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:127917"/>
          <criterion comment="finch-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:127865"/>
          <criterion comment="libpurple is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:128086"/>
          <criterion comment="libpurple-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:128160"/>
          <criterion comment="libpurple-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:128048"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:127675"/>
          <criterion comment="pidgin-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:127801"/>
          <criterion comment="pidgin-docs is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:127924"/>
          <criterion comment="pidgin-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:128105"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27282" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0742 -- 389-ds-base security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0742.html" ref_id="ELSA-2013-0742"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1897" ref_id="CVE-2013-1897"/>
        <description>[1.2.11.15-14]
- Resolves: Bug 929107 - ns-slapd crashes sporadically with segmentation fault in libslapd.so (ticket 627)
- Resolves: Bug 929114 - cleanAllRUV task fails to cleanup config upon completion (ticket 623)

[1.2.11.15-13]
- Resolves: Bug 929114 - cleanAllRUV task fails to cleanup config upon completion (ticket 623)
- Resolves: Bug 929111 - Coverity issue 13091
- Resolves: Bug 929196 - Deadlock in DNA plug-in (ticket 634)
- Resolves: Bug 929107 - ns-slapd crashes sporadically with segmentation fault in libslapd.so (ticket 627)
- Resolves: Bug 929115 - crash in aci evaluation (ticket 628)
- Resolves: Bug 923240 - unintended information exposure when anonymous access is set to rootdse (ticket 47308)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:41.867-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:21.778-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:19.024-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:32:11.221-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:32:11.221-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-14.el6_4" test_ref="oval:org.mitre.oval:tst:129484"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-14.el6_4" test_ref="oval:org.mitre.oval:tst:129763"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-14.el6_4" test_ref="oval:org.mitre.oval:tst:129779"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27280" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1326 -- php53 and php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1326.html" ref_id="ELSA-2014-1326"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2497" ref_id="CVE-2014-2497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3587" ref_id="CVE-2014-3587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3597" ref_id="CVE-2014-3597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4670" ref_id="CVE-2014-4670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4698" ref_id="CVE-2014-4698"/>
        <description>[5.3.3-27.2]
        - spl: fix use-after-free in ArrayIterator due to object
          change during sorting. CVE-2014-4698
        - spl: fix use-after-free in SPL Iterators. CVE-2014-4670
        - gd: fix NULL pointer dereference in gdImageCreateFromXpm.
          CVE-2014-2497
        - fileinfo: fix incomplete fix for CVE-2012-1571 in
          cdf_read_property_info. CVE-2014-3587
        - core: fix incomplete fix for CVE-2014-4049 DNS TXT
          record parsing. CVE-2014-3597</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:02.175-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:20.554-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:18.405-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126797"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126454"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126850"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126514"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126592"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126773"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126489"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126874"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126563"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126286"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126903"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126883"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125998"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126742"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126219"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126963"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126300"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126964"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126155"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126923"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:126661"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126409"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126833"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126474"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126828"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126153"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126909"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126548"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126971"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126802"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126226"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126737"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126375"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126896"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126830"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126641"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126924"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126957"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126695"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126522"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126922"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126935"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126728"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126796"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126713"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126723"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126611"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:126683"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27279" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1806 -- samba and samba3x security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1806.html" ref_id="ELSA-2013-1806"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408" ref_id="CVE-2013-4408"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475" ref_id="CVE-2013-4475"/>
        <description>[3.6.9-167]
- resolves: #1018037 - Fix CVE-2013-4408.

[3.6.9-165]
- resolves: #1028086 - Fix CVE-2013-4475.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:33.710-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:20.143-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:18.187-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:56:57.005-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:56:57.005-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128360"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128127"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:127817"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128406"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:127839"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128298"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:127434"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:128432"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:127879"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:127665"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128038"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:127451"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128348"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128306"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128201"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128411"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128220"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128051"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128342"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:128446"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27278" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3011 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3011.html" ref_id="ELSA-2014-3011"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2929" ref_id="CVE-2013-2929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263" ref_id="CVE-2013-7263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7265" ref_id="CVE-2013-7265"/>
        <description>[3.8.13-26.1.1.el6uek]
- inet: fix addr_len/msg->msg_namelen assignment in recv_error and rxpmtu functions (Hannes Frederic Sowa)  [18247287]  {CVE-2013-7263} {CVE-2013-7265}
- inet: prevent leakage of uninitialized memory to user in recv syscalls (Hannes Frederic Sowa)  [18238377]  {CVE-2013-7263} {CVE-2013-7265}
- exec/ptrace: fix get_dumpable() incorrect tests (Kees Cook)  [18238348]  {CVE-2013-2929}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:24.179-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:19.650-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:18.058-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35292 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:04.043-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:13.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-26.1.1.el6uek is earlier than 0:0.4.2-3.el6" test_ref="oval:org.mitre.oval:tst:127582"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-26.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128003"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-26.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:127630"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-26.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128010"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-26.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128054"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-26.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:127253"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-26.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:128107"/>
          <criterion comment="kernel-uek-headers is earlier than 0:3.8.13-26.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:127687"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27277" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1849 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1849.html" ref_id="ELSA-2011-1849"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4127" ref_id="CVE-2011-4127"/>
        <description>[2.6.32-220.2.1.el6]
- [dm] fixing test for NULL pointer testing (Paolo Bonzini) [752379 752380] {CVE-2011-4127}

[2.6.32-220.1.1.el6]
- [dm] do not forward ioctls from logical volumes to the underlying device (Paolo Bonzini) [752379 752380] {CVE-2011-4127}
- [block] fail SCSI passthrough ioctls on partition devices (Paolo Bonzini) [752379 752380] {CVE-2011-4127}
- [block] add and use scsi_blk_cmd_ioctl (Paolo Bonzini) [752379 752380] {CVE-2011-4127}
- [x86] amd: Fix align_va_addr kernel parameter (Frank Arnold) [758028 753237]
- [md] RAID1: Do not call md_raid1_unplug_device while holding spinlock (Jonathan E Brassow) [755545 752528]
- [pci] intel-iommu: Default to non-coherent for domains unattached to iommus (Don Dutile) [757671 746484]
- [x86] initialize min_delta_ns in one_hpet_msi_clockevent() (Prarit Bhargava) [756426 728315]
- [x86] Update hpet_next_event() (Prarit Bhargava) [756426 728315]
- [kernel] sched: Use resched IPI to kick off the nohz idle balance (Vivek Goyal) [750459 717179]
- [drm] i915: enable ring freq scaling, RC6 and graphics turbo on Ivy Bridge (Prarit Bhargava) [758513 752163]
- [drm] i915: load a ring frequency scaling table (Prarit Bhargava) [758513 752163]
- [x86] cpufreq: expose a cpufreq_quick_get_max routine (Prarit Bhargava) [758513 752163]
- [sched] Cleanup/optimize clock updates (Larry Woodman) [751403 750237]
- [sched] fix skip_clock_update optimization (Larry Woodman) [751403 750237]
- [block] virtio-blk: Use ida to allocate disk index (Michael S. Tsirkin) [756427 692767]
- [virt] virtio_blk: Replace cryptic number with the macro (Michael S. Tsirkin) [756427 692767]
- [kernel] ida: simplified functions for id allocation (Michael S. Tsirkin) [756427 692767]
- [virt] revert virtio-blk: Use ida to allocate disk index (Aristeu Rozanski) [756427 692767]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:19.265-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:19.358-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:17.887-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:58:06.683-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:58:06.683-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:132531"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:132950"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:132944"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:132962"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:132660"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:133028"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:132529"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:132968"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:132805"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27273" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0015 -- openssl security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0015.html" ref_id="ELSA-2014-0015"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4353" ref_id="CVE-2013-4353"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6449" ref_id="CVE-2013-6449"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6450" ref_id="CVE-2013-6450"/>
        <description>[1.0.1e-16.4]
- fix CVE-2013-4353 - Invalid TLS handshake crash

[1.0.1e-16.3]
- fix CVE-2013-6450 - possible MiTM attack on DTLS1

[1.0.1e-16.2]
- fix CVE-2013-6449 - crash when version in SSL structure is incorrect</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:41.985-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:15.647-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:16.630-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T10:59:54.061-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T10:59:54.061-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:127793"/>
          <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:127918"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:128041"/>
          <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:128149"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27272" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0517 -- util-linux-ng security, bug fix and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>util-linux-ng</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0517.html" ref_id="ELSA-2013-0517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0157" ref_id="CVE-2013-0157"/>
        <description>[2.17.2-12.9]
- fix #892471 - CVE-2013-0157 mount folder existence information disclosure

[2.17.2-12.8]
- fix #679833 - [RFE] tailf should support 
- fix #719927 - [RFE] add adjtimex --compare functionality to hwclock
- fix #730272 - losetup does not warn if backing file is &lt; 512 bytes
- fix #730891 - document cfdisk and sfdisk incompatibility with 4096-bytes sectors
- fix #736245 - lscpu segfault on non-uniform cpu configuration
- fix #783514 - default barrier setting for EXT3 filesystems in mount manpage is wrong
- fix #790728 - blkid ignores swap UUIDs if the first byte is a zero byte
- fix #818621 - lsblk should not open device it prints info about
- fix #819945 - hwclock --systz causes a system time jump
- fix #820183 - mount(8) man page should include relatime in defaults definition
- fix #823008 - update to the latest upstream lscpu and chcpu
- fix #837935 - lscpu coredumps on a system with 158 active processors
- fix #839281 - inode_readahead for ext4 should be inode_readahead_blks
- fix #845477 - Duplicate SElinux mount options cause mounting from the commandline to fail
- fix #845971 - while reading /etc/fstab, mount command returns a device before a directory
- fix #858009 - login doesn't update /var/run/utmp properly
- fix #809449 - Backport inverse tree (-s) option for lsblk and related patches
- fix #809139 - lsblk option -D missing in manpage</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:01.276-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:15.405-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:16.528-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:46:46.494-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:46:46.494-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="util-linux-ng is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:130364"/>
          <criterion comment="libblkid is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:130204"/>
          <criterion comment="libblkid-devel is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:129637"/>
          <criterion comment="libuuid is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:130139"/>
          <criterion comment="libuuid-devel is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:130062"/>
          <criterion comment="uuidd is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:130106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27271" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1084 -- libsndfile security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libsndfile</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1084.html" ref_id="ELSA-2011-1084"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2696" ref_id="CVE-2011-2696"/>
        <description>[1.0.20-3.1]
- fixes integer overflow by processing certain PAF audio files (#722841)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:34">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:43.261-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:15.159-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:16.390-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:25:15.196-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:25:15.196-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libsndfile is earlier than 0:1.0.20-3.el6_1.1" test_ref="oval:org.mitre.oval:tst:133250"/>
          <criterion comment="libsndfile-devel is earlier than 0:1.0.20-3.el6_1.1" test_ref="oval:org.mitre.oval:tst:133513"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27270" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0919 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0919.html" ref_id="ELSA-2014-0919"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1547" ref_id="CVE-2014-1547"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1555" ref_id="CVE-2014-1555"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1556" ref_id="CVE-2014-1556"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1557" ref_id="CVE-2014-1557"/>
        <description>[24.7.0-1.0.1.el6_5]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one

[24.7.0-1]
- Update to 24.7.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:10.760-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:14.608-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:16.126-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.7.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126961"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:24.7.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27269" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1144 -- nss, nss-util, nss-softokn, and nspr security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-softokn</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1144.html" ref_id="ELSA-2013-1144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0791" ref_id="CVE-2013-0791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1620" ref_id="CVE-2013-1620"/>
        <description>It was discovered that NSS leaked timing information when decrypting
TLS/SSL and DTLS protocol encrypted records when CBC-mode cipher suites
were used. A remote attacker could possibly use this flaw to retrieve plain
text from the encrypted packets by using a TLS/SSL or DTLS server as a
padding oracle. (CVE-2013-1620)

An out-of-bounds memory read flaw was found in the way NSS decoded certain
certificates. If an application using NSS decoded a malformed certificate,
it could cause the application to crash. (CVE-2013-0791)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:29.131-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:14.196-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:15.915-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:15:58.302-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:15:58.302-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.9.5-2.el6_4" test_ref="oval:org.mitre.oval:tst:129124"/>
          <criterion comment="nss is earlier than 0:3.14.3-4.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129244"/>
          <criterion comment="nss-softokn is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:128856"/>
          <criterion comment="nss-util is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:129038"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.5-2.el6_4" test_ref="oval:org.mitre.oval:tst:129257"/>
          <criterion comment="nss-devel is earlier than 0:3.14.3-4.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128644"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.14.3-4.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128870"/>
          <criterion comment="nss-softokn-devel is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:129035"/>
          <criterion comment="nss-softokn-freebl is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:129151"/>
          <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:128890"/>
          <criterion comment="nss-sysinit is earlier than 0:3.14.3-4.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128996"/>
          <criterion comment="nss-tools is earlier than 0:3.14.3-4.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129123"/>
          <criterion comment="nss-util-devel is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:129188"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27267" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0876 -- net-snmp security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>net-snmp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0876.html" ref_id="ELSA-2012-0876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2141" ref_id="CVE-2012-2141"/>
        <description>[1:5.5-41]
- moved /var/lib/net-snmp fro net-snmp to net-snmp-libs package
  (#822480)

[1:5.5-40]
- fixed CVE-2012-2141 (#820100)

[1:5.5-39]
- fixed proxying of out-of-tree GETNEXT requests (#799291)

[1:5.5-38]
- fixed snmpd crashing with many AgentX subagent (#749227)
- fixed SNMPv2-MIB::sysObjectID value when sysObjectID config file
  option with long OID was used (#786931)
- fixed value of BRIDGE-MIB::dot1dBasePortIfIndex.1 (#740172)
- fixed parsing of proxy snmpd.conf option not to enable
  verbose logging by default (#746903)
- added new realStorageUnits config file option to support
  disks > 16 TB in hrStorageTable (#741789)
- added vxfs, reiserfs and ocfs2 filesystem support to hrStorageTable
  (#746903)
- fixed snmpd sigsegv when embedded perl script registers one handler
  twice (#748907)
- fixed setting of SNMP-TARGET-MIB::snmpTargetAddrRowStatus via
  SNMP-SET request on 64-bit platforms (#754275)
- fixed crash when /var/lib/net-snmp/mib_indexes/ files have wrong
  SELinux context (#754971)
- fixed memory leak when agentx subagent disconnects in the middle
  of request processing (#736580)
- fixed slow (re-)loads of TCP-MIB::tcpConnectionTable (#789909)
- removed 'error finding row index in _ifXTable_container_row_restore'
  error message (#788954)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:12.782-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:13.165-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:15.646-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:04:50.772-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:04:50.772-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="net-snmp is earlier than 0:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:131789"/>
          <criterion comment="net-snmp-devel is earlier than 0:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:131745"/>
          <criterion comment="net-snmp-libs is earlier than 0:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:131810"/>
          <criterion comment="net-snmp-perl is earlier than 0:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:131654"/>
          <criterion comment="net-snmp-python is earlier than 0:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:131512"/>
          <criterion comment="net-snmp-utils is earlier than 0:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:131584"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27266" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3070 -- Unbreakable Enterprise kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3070.html" ref_id="ELSA-2014-3070"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2930" ref_id="CVE-2013-2930"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4579" ref_id="CVE-2013-4579"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1690" ref_id="CVE-2014-1690"/>
        <description>kernel-uek
          [3.8.13-44]
          - net: Use netlink_ns_capable to verify the permisions of netlink messages (Eric W. Biederman)  [Orabug: 19404229]  {CVE-2014-0181}
          - net: Add variants of capable for use on netlink messages (Eric W. Biederman)  [Orabug: 19404229] 
          - net: Add variants of capable for use on on sockets (Eric W. Biederman)  [Orabug: 19404229] 
          - netlink: Rename netlink_capable netlink_allowed (Eric W. Biederman)  [Orabug: 19404229] 
          - sctp: Fix sk_ack_backlog wrap-around problem (Xufeng Zhang)  [Orabug: 19404238]  {CVE-2014-4667}
          - Revert 'xen/fb: allow xenfb initialization for hvm guests' (Vaughan Cao)  [Orabug: 19320529]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:17.523-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:12.793-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:15.432-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35000 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:03.850-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:12.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-44.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:126599"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-44.el6uek" test_ref="oval:org.mitre.oval:tst:126024"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-44.el6uek" test_ref="oval:org.mitre.oval:tst:126803"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-44.el6uek" test_ref="oval:org.mitre.oval:tst:126432"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-44.el6uek" test_ref="oval:org.mitre.oval:tst:126893"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-44.el6uek" test_ref="oval:org.mitre.oval:tst:126575"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-44.el6uek" test_ref="oval:org.mitre.oval:tst:126996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27264" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1645 -- Oracle Linux 6 kernel update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1645.html" ref_id="ELSA-2013-1645"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6542" ref_id="CVE-2012-6542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1929" ref_id="CVE-2013-1929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6545" ref_id="CVE-2012-6545"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3231" ref_id="CVE-2013-3231"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2164" ref_id="CVE-2013-2164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2234" ref_id="CVE-2013-2234"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2851" ref_id="CVE-2013-2851"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343" ref_id="CVE-2013-0343"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4345" ref_id="CVE-2013-4345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1928" ref_id="CVE-2013-1928"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2888" ref_id="CVE-2013-2888"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2889" ref_id="CVE-2013-2889"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2892" ref_id="CVE-2013-2892"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4387" ref_id="CVE-2013-4387"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4591" ref_id="CVE-2013-4591"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4592" ref_id="CVE-2013-4592"/>
        <description>[2.6.32-431] 

- [md] Disabling of TRIM on RAID5 for RHEL6.5 was too aggressive (Jes Sorensen) [1028426]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:29.128-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:10.400-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:14.538-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:128212"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:127677"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:128569"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:128539"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:128521"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:128516"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:128624"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:128587"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:128568"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:128456"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27262" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1671 -- rsyslog5 and rsyslog security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>rsyslog</product>
          <product>rsyslog5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1671.html" ref_id="ELSA-2014-1671"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3634" ref_id="CVE-2014-3634"/>
        <description>[5.8.12-5.0.1]
        - use setsid() to get a controlling session and process group [Orabug: 17364545]
        [5.8.12-5]
        - fix CVE-2014-3634
          resolves: #1149158</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:23.766-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:09.573-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:14.116-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rsyslog5 is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126613"/>
            <criterion comment="rsyslog5-gnutls is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126495"/>
            <criterion comment="rsyslog5-gssapi is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126582"/>
            <criterion comment="rsyslog5-mysql is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:125811"/>
            <criterion comment="rsyslog5-pgsql is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126734"/>
            <criterion comment="rsyslog5-snmp is earlier than 0:5.8.12-5.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126646"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rsyslog is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126557"/>
            <criterion comment="rsyslog-gnutls is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126682"/>
            <criterion comment="rsyslog-gssapi is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126771"/>
            <criterion comment="rsyslog-mysql is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126415"/>
            <criterion comment="rsyslog-pgsql is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126787"/>
            <criterion comment="rsyslog-relp is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126736"/>
            <criterion comment="rsyslog-snmp is earlier than 0:5.8.10-9.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126601"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27259" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1801 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1801.html" ref_id="ELSA-2013-1801"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2141" ref_id="CVE-2013-2141"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4470" ref_id="CVE-2013-4470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6367" ref_id="CVE-2013-6367"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6368" ref_id="CVE-2013-6368"/>
        <description>[2.6.32-431.1.2]
- [x86] kvm: fix cross page vapic_addr access (Paolo Bonzini) [1032214 1032215] {CVE-2013-6368}
- [x86] kvm: fix division by zero in apic_get_tmcct (Paolo Bonzini) [1032212 1032213] {CVE-2013-6367}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:20.140-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:08.429-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:13.478-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:25:24.592-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:25:24.592-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:128313"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:127972"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:128345"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:128384"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:128257"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:128277"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:128268"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:127965"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:127961"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:128357"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27258" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1569 -- wireshark security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1569.html" ref_id="ELSA-2013-1569"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4285" ref_id="CVE-2012-4285"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4289" ref_id="CVE-2012-4289"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4290" ref_id="CVE-2012-4290"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4291" ref_id="CVE-2012-4291"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2392" ref_id="CVE-2012-2392"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3825" ref_id="CVE-2012-3825"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4288" ref_id="CVE-2012-4288"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4292" ref_id="CVE-2012-4292"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5595" ref_id="CVE-2012-5595"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5597" ref_id="CVE-2012-5597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5598" ref_id="CVE-2012-5598"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5599" ref_id="CVE-2012-5599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5600" ref_id="CVE-2012-5600"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6056" ref_id="CVE-2012-6056"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6059" ref_id="CVE-2012-6059"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6060" ref_id="CVE-2012-6060"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6061" ref_id="CVE-2012-6061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6062" ref_id="CVE-2012-6062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3557" ref_id="CVE-2013-3557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3559" ref_id="CVE-2013-3559"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3561" ref_id="CVE-2013-3561"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4081" ref_id="CVE-2013-4081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4083" ref_id="CVE-2013-4083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4927" ref_id="CVE-2013-4927"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4931" ref_id="CVE-2013-4931"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4932" ref_id="CVE-2013-4932"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4933" ref_id="CVE-2013-4933"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4934" ref_id="CVE-2013-4934"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4935" ref_id="CVE-2013-4935"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4936" ref_id="CVE-2013-4936"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5721" ref_id="CVE-2013-5721"/>
        <description>[1.8.10-4.0.1.el6]

- Add oracle-ocfs2-network.patch to allow disassembly of OCFS2 interconnect</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:03.672-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:05.476-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:12.396-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="wireshark is earlier than 0:1.8.10-4.0.1.el6" test_ref="oval:org.mitre.oval:tst:128417"/>
          <criterion comment="wireshark-devel is earlier than 0:1.8.10-4.0.1.el6" test_ref="oval:org.mitre.oval:tst:128476"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.8.10-4.0.1.el6" test_ref="oval:org.mitre.oval:tst:128669"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27256" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1140 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1140.html" ref_id="ELSA-2013-1140"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1701" ref_id="CVE-2013-1701"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1709" ref_id="CVE-2013-1709"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1710" ref_id="CVE-2013-1710"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1713" ref_id="CVE-2013-1713"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1714" ref_id="CVE-2013-1714"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1717" ref_id="CVE-2013-1717"/>
        <description>firefox
[17.0.8-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.8-1]
- Update to 17.0.8 ESR

xulrunner
[17.0.8-3.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.8-3]
- Update to 17.0.8 ESR Build 2

[17.0.8-2]
- Added fix for rhbz#990921 - firefox does not build with
  required nss/nspr

[17.0.8-1]
- Update to 17.0.8 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:11.811-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:04.572-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:11.984-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:28:15.023-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:28:15.023-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.8-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129146"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129180"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128874"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.8-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128812"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128986"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129283"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27254" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2034 -- Unbreakable Enterprise kernel Security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2034.html" ref_id="ELSA-2012-2034"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2313" ref_id="CVE-2012-2313"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2390" ref_id="CVE-2012-2390"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3430" ref_id="CVE-2012-3430"/>
        <description>[2.6.39-200.32.1]
- dl2k: Clean up rio_ioctl (Stephan Mueller) [Orabug: 14680245] {CVE-2012-2313}
- hugetlb: fix resv_map leak in error path (Christoph Lameter) [Orabug: 14680284] {CVE-2012-2390}
- rds: set correct msg_namelen (Jay Fenlason) [Orabug: 14680018] {CVE-2012-3430}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:37.440-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:03.676-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:11.648-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130949"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:131168"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130792"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130946"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130823"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.32.1.el5uek" test_ref="oval:org.mitre.oval:tst:130996"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:131187"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:131195"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:130230"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:131037"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:131152"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.32.1.el6uek" test_ref="oval:org.mitre.oval:tst:130794"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27253" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0246 -- gnutls security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0246.html" ref_id="ELSA-2014-0246"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0092" ref_id="CVE-2014-0092"/>
        <description>[2.8.5-13]
- fix CVE-2014-0092 (#1069890)

[2.8.5-12]
- fix CVE-2013-2116 - fix DoS regression in CVE-2013-1619
  upstream patch (#966754)

[2.8.5-11]
- fix CVE-2013-1619 - fix TLS-CBC timing attack (#908238)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:18.352-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:03.461-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:11.554-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:18:15.353-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:18:15.353-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gnutls is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:127354"/>
          <criterion comment="gnutls-devel is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:128024"/>
          <criterion comment="gnutls-guile is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:127869"/>
          <criterion comment="gnutls-utils is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:128091"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27252" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0924 -- kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0924.html" ref_id="ELSA-2014-0924"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943" ref_id="CVE-2014-4943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4699" ref_id="CVE-2014-4699"/>
        <description>[2.6.32-431.20.5]
- [netdrv] pppol2tp: fail when socket option level is not SOL_PPPOL2TP [1119461 1119462] {CVE-2014-4943}

[2.6.32-431.20.4]
- [kernel] utrace: force IRET path after utrace_finish_vfork() (Oleg Nesterov) [1115932 1115933] {CVE-2014-4699}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:29.056-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:03.101-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:11.432-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:126392"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:126720"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:127261"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:127089"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:127029"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:127255"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:127139"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:127307"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:126854"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:127189"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27250" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3043 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3043.html" ref_id="ELSA-2014-3043"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1737" ref_id="CVE-2014-1737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1738" ref_id="CVE-2014-1738"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6378" ref_id="CVE-2013-6378"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1874" ref_id="CVE-2014-1874"/>
        <description>kernel-uek
[2.6.32-400.36.3uek]
- fix autofs/afs/etc. magic mountpoint breakage (Al Viro)  [Orabug: 19028505]  {CVE-2014-0203}
- SELinux:  Fix kernel BUG on empty security contexts. (Stephen Smalley)  [Orabug: 19028381]  {CVE-2014-1874}
- floppy: don't write kernel-only members to FDRAWCMD ioctl output (Matthew Daley)  [Orabug: 19028446]  {CVE-2014-1738}
- floppy: ignore kernel-only members in FDRAWCMD ioctl input (Matthew Daley)  [Orabug: 19028439]  {CVE-2014-1737}
- libertas: potential oops in debugfs (Dan Carpenter)  [Orabug: 19028417]  {CVE-2013-6378}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:10.261-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:02.291-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:10.971-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35309 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:59.411-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:12.227-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:126800"/>
            <criterion comment="mlnx_en-2.6.32-400.36.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127213"/>
            <criterion comment="ofa-2.6.32-400.36.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127465"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127385"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127540"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127615"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127163"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127436"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.3.el5uek" test_ref="oval:org.mitre.oval:tst:127388"/>
            <criterion comment="mlnx_en-2.6.32-400.36.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127216"/>
            <criterion comment="ofa-2.6.32-400.36.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127587"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127566"/>
            <criterion comment="mlnx_en-2.6.32-400.36.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127596"/>
            <criterion comment="ofa-2.6.32-400.36.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127581"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127437"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127421"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127461"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:126746"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127604"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.3.el6uek" test_ref="oval:org.mitre.oval:tst:127173"/>
            <criterion comment="mlnx_en-2.6.32-400.36.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126623"/>
            <criterion comment="ofa-2.6.32-400.36.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126932"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27249" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2007 -- Unbreakable Enterprise kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2007.html" ref_id="ELSA-2012-2007"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0879" ref_id="CVE-2012-0879"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1090" ref_id="CVE-2012-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1097" ref_id="CVE-2012-1097"/>
        <description>[2.6.32-300.21.1.el6uek]
- regset: Return -EFAULT, not -EIO, on host-side memory fault (H. Peter Anvin)
  CVE-2012-1097
- regset: Prevent null pointer reference on readonly regsets (H. Peter Anvin)
  CVE-2012-1097
- cifs: fix dentry refcount leak when opening a FIFO on lookup (Jeff Layton)
  CVE-2012-1090
- block: Fix io_context leak after failure of clone with CLONE_IO (Louis
  Rilling)  CVE-2012-0879</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:10.889-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:01.748-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:10.651-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:132122 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:02.272-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:11.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:131894"/>
            <criterion comment="mlnx_en-2.6.32-300.21.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132427"/>
            <criterion comment="ofa-2.6.32-300.21.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131845"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132389"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132347"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132418"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132213"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132400"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:132435"/>
            <criterion comment="mlnx_en-2.6.32-300.21.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:132122"/>
            <criterion comment="ofa-2.6.32-300.21.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:132304"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:131573"/>
            <criterion comment="mlnx_en-2.6.32-300.21.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132489"/>
            <criterion comment="ofa-2.6.32-300.21.1.el6uek is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132573"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:131591"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132203"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132123"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132338"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132130"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:132319"/>
            <criterion comment="mlnx_en-2.6.32-300.21.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:132424"/>
            <criterion comment="ofa-2.6.32-300.21.1.el6uekdebug is earlier than 0:1.5.1-4.0.47" test_ref="oval:org.mitre.oval:tst:132080"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27246" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0369 -- python-sqlalchemy security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python-sqlalchemy</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0369.html" ref_id="ELSA-2012-0369"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0805" ref_id="CVE-2012-0805"/>
        <description>[0.5.5-3]
- sanitize inputs to limit() and offset()
Resolves: CVE-2012-0805</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:18.030-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:00.662-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:10.089-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:59:45.170-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:59:45.170-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="python-sqlalchemy is earlier than 0:0.5.5-3.el6_2" test_ref="oval:org.mitre.oval:tst:132676"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27245" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0505 -- squid security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0505.html" ref_id="ELSA-2013-0505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5643" ref_id="CVE-2012-5643"/>
        <description>[7:3.1.10-16]
- Resolves: #888198 - CVE-2012-5643: improved upstream patch

[7:3.1.10-15]
- Reverts: #861062 - Squid delays on FQDNs that don't contains AAAA record

[7:3.1.10-14]
- Resolves: #888198 - CVE-2012-5643: patch

[7:3.1.10-13]
- Resolves: #888198 - CVE-2012-5643: DoS (excessive resource consumption)

[7:3.1.10-12]
- Resolves #861062 - add configure directive --enable-internal-dns

[7:3.1.10-11	]
- Resolves #861062 - Squid delays on FQDNs that don't contains AAAA record

[7:3.1.10-10]
- Resolves #798090 - Client timeout uses server-side 'read_timeout'
- Resolves #833086 - Private md5 hash function does not comply FIPS
- Resolves #782732 - Squid crashes by segfault when it reboots
- Resolves #797571 - Squid userid is not added to wbpriv group
- Disable strict-error-checking on account of squid-fips.patch</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:43.845-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:03:00.414-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:09.970-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:53:18.712-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:53:18.712-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="squid is earlier than 0:3.1.10-16.el6" test_ref="oval:org.mitre.oval:tst:130258"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27244" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0561 -- curl security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0561.html" ref_id="ELSA-2014-0561"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0015" ref_id="CVE-2014-0015"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0138" ref_id="CVE-2014-0138"/>
        <description>[7.19.7-37.el6_5.3]
- fix re-use of wrong HTTP NTLM connection (CVE-2014-0015)
- fix connection re-use when using different log-in credentials (CVE-2014-0138)

[7.19.7-37.el6_5.2]
- fix authentication failure when server offers multiple auth options (#1096797)

[7.19.7-37.el6_5.1]
- refresh expired cookie in test172 from upstream test-suite (#1092486)
- fix a memory leak caused by write after close (#1092479)
- nss: implement non-blocking SSL handshake (#1092480)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:10.239-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:59.982-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:09.799-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:42:59.496-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:42:59.496-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="curl is earlier than 0:7.19.7-37.el6_5.3" test_ref="oval:org.mitre.oval:tst:127394"/>
          <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_5.3" test_ref="oval:org.mitre.oval:tst:127633"/>
          <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_5.3" test_ref="oval:org.mitre.oval:tst:127468"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27243" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3085 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3085.html" ref_id="ELSA-2014-3085"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3611" ref_id="CVE-2014-3611"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3185" ref_id="CVE-2014-3185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3181" ref_id="CVE-2014-3181"/>
        <description>[2.6.39-400.215.12]
- USB: whiteheat: Added bounds checking for bulk command response (James Forshaw)  [Orabug: 19849335]  {CVE-2014-3185}
- HID: fix a couple of off-by-ones (Jiri Kosina)  [Orabug: 19849318]  {CVE-2014-3181}
- KVM: x86: Improve thread safety in pit (Andy Honig)  [Orabug: 19905687]  {CVE-2014-3611}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:07.591-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:59.791-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:09.644-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126643"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126515"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126639"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126260"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126156"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.12.el5uek" test_ref="oval:org.mitre.oval:tst:126562"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126324"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:125707"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126648"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126541"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126461"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.12.el6uek" test_ref="oval:org.mitre.oval:tst:126700"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27242" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3010 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3010.html" ref_id="ELSA-2014-3010"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2929" ref_id="CVE-2013-2929"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263" ref_id="CVE-2013-7263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7265" ref_id="CVE-2013-7265"/>
        <description>[2.6.32-400.34.3]
- inet: fix addr_len/msg->msg_namelen assignment in recv_error and rxpmtu functions (Hannes Frederic Sowa)  [18247290]  {CVE-2013-7263} {CVE-2013-7265}

[2.6.32-400.34.2]
- exec/ptrace: fix get_dumpable() incorrect tests (Kees Cook)  [18239033]  {CVE-2013-2929} {CVE-2013-2929}
- inet: prevent leakage of uninitialized memory to user in recv syscalls (Hannes Frederic Sowa)  [18239036]  {CVE-2013-7263} {CVE-2013-7265}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:33.289-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:59.257-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:09.364-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35357 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:26:58.886-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:10.744-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:128142"/>
            <criterion comment="mlnx_en-2.6.32-400.34.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127422"/>
            <criterion comment="ofa-2.6.32-400.34.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128079"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127975"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127872"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127787"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:128033"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127964"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.3.el5uek" test_ref="oval:org.mitre.oval:tst:127600"/>
            <criterion comment="mlnx_en-2.6.32-400.34.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127926"/>
            <criterion comment="ofa-2.6.32-400.34.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127894"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127708"/>
            <criterion comment="mlnx_en-2.6.32-400.34.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127583"/>
            <criterion comment="ofa-2.6.32-400.34.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127963"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127732"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127830"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127479"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:128005"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127356"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.3.el6uek" test_ref="oval:org.mitre.oval:tst:127510"/>
            <criterion comment="mlnx_en-2.6.32-400.34.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128035"/>
            <criterion comment="ofa-2.6.32-400.34.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127861"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27241" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1779 -- mod_nss security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>mod_nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1779.html" ref_id="ELSA-2013-1779"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4566" ref_id="CVE-2013-4566"/>
        <description>[1.0.8-19]
- Resolves: CVE-2013-4566
- Bugzilla Bug #1030265 - mod_nss: incorrect handling of NSSVerifyClient in
  directory context [rhel-6.5.z]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:37.086-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:59.031-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:09.237-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:06:02.923-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:06:02.923-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="mod_nss is earlier than 0:1.0.8-8.el5_10" test_ref="oval:org.mitre.oval:tst:127764"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="mod_nss is earlier than 0:1.0.8-19.el6_5" test_ref="oval:org.mitre.oval:tst:128358"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27237" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0742 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0742.html" ref_id="ELSA-2014-0742"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1533" ref_id="CVE-2014-1533"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1538" ref_id="CVE-2014-1538"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1541" ref_id="CVE-2014-1541"/>
        <description>[24.6.0-1.0.1.el6_5]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[24.6.0-1]
- Update to 24.6.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:25.479-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:57.584-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:08.511-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:41:48.641-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:41:48.641-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127418"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127117"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27236" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3084 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3084.html" ref_id="ELSA-2014-3084"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3611" ref_id="CVE-2014-3611"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3645" ref_id="CVE-2014-3645"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3646" ref_id="CVE-2014-3646"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3185" ref_id="CVE-2014-3185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3181" ref_id="CVE-2014-3181"/>
        <description>kernel-uek
[3.8.13-44.1.4.el7uek]
- USB: whiteheat: Added bounds checking for bulk command response (James Forshaw)  [Orabug: 19849334]  {CVE-2014-3185}
- HID: fix a couple of off-by-ones (Jiri Kosina)  [Orabug: 19849317]  {CVE-2014-3181}
- kvm: vmx: handle invvpid vm exit gracefully (Petr Matousek)  [Orabug: 19906300]  {CVE-2014-3646}
- nEPT: Nested INVEPT (Nadav Har'El)  [Orabug: 19906267]  {CVE-2014-3645}
- KVM: x86: Improve thread safety in pit (Andy Honig)  [Orabug: 19905686]  {CVE-2014-3611}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:23.094-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:57.074-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:08.294-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35195 - Corrected package names in objects and versions in states." date="2015-02-26T19:19:00.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:27:04.300-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:09.825-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-44.1.4.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:126304"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-44.1.4.el6uek" test_ref="oval:org.mitre.oval:tst:126368"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-44.1.4.el6uek" test_ref="oval:org.mitre.oval:tst:126273"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-44.1.4.el6uek" test_ref="oval:org.mitre.oval:tst:126568"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-44.1.4.el6uek" test_ref="oval:org.mitre.oval:tst:126523"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-44.1.4.el6uek" test_ref="oval:org.mitre.oval:tst:125750"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-44.1.4.el6uek" test_ref="oval:org.mitre.oval:tst:126625"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27235" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1272 -- libvirt security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1272.html" ref_id="ELSA-2013-1272"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4296" ref_id="CVE-2013-4296"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4311" ref_id="CVE-2013-4311"/>
        <description>[0.10.2-18.0.1.el6_4.14]
- Replace docs/et.png in tarball with blank image

[0.10.2-18.el6_4.14]
- spec: Update requirements to pick up rebuilt polkit (CVE-2013-4311)

[0.10.2-18.el6_4.13]
- spec: Fix messed up dependency on polkit (CVE-2013-4311)

[0.10.2-18.el6_4.12]
- Introduce APIs for splitting/joining strings (rhbz#1006265)
- Rename virKillProcess to virProcessKill (rhbz#1006265)
- Rename virPid{Abort, Wait} to virProcess{Abort, Wait} (rhbz#1006265)
- Rename virCommandTranslateStatus to virProcessTranslateStatus (rhbz#1006265)
- Move virProcessKill into virprocess.{h, c} (rhbz#1006265)
- Move virProcess{Kill, Abort, TranslateStatus} into virprocess.{c, h} (rhbz#1006265)
- Include process start time when doing polkit checks (rhbz#1006265)
- Add support for using 3-arg pkcheck syntax for process (CVE-2013-4311)

[0.10.2-18.el6_4.11]
- Fix crash in remoteDispatchDomainMemoryStats (CVE-2013-4296)

[0.10.2-18.el6_4.10]
- qemu: Avoid leaking uri in qemuMigrationPrepareDirect (rhbz#984578)
- qemu: Fix double free in qemuMigrationPrepareDirect (rhbz#984578)
[when parsing a single device (rhbz#1003934)]
- Plug leak in virCgroupMoveTask (rhbz#984556)
- Fix invalid read in virCgroupGetValueStr (rhbz#984561)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:58:59.305-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:56.775-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:08.159-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:00:22.566-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:00:22.566-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.10.2-18.0.1.el6_4.14" test_ref="oval:org.mitre.oval:tst:128598"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-18.0.1.el6_4.14" test_ref="oval:org.mitre.oval:tst:128373"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-18.0.1.el6_4.14" test_ref="oval:org.mitre.oval:tst:129093"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-18.0.1.el6_4.14" test_ref="oval:org.mitre.oval:tst:129039"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27234" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1542 -- samba security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1542.html" ref_id="ELSA-2013-1542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0213" ref_id="CVE-2013-0213"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0214" ref_id="CVE-2013-0214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124" ref_id="CVE-2013-4124"/>
        <description>[3.6.9-164]

- resolves: #1008574 - Fix offline logon cache not updating for cross child

                       domain group membership.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:19.107-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:56.412-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:07.932-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128657"/>
          <criterion comment="libsmbclient is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128039"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128408"/>
          <criterion comment="samba-client is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128049"/>
          <criterion comment="samba-common is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128372"/>
          <criterion comment="samba-doc is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128416"/>
          <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128680"/>
          <criterion comment="samba-swat is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128427"/>
          <criterion comment="samba-winbind is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128467"/>
          <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128116"/>
          <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128693"/>
          <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:128309"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27233" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1052 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1052.html" ref_id="ELSA-2014-1052"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3505" ref_id="CVE-2014-3505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3506" ref_id="CVE-2014-3506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3507" ref_id="CVE-2014-3507"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3508" ref_id="CVE-2014-3508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3509" ref_id="CVE-2014-3509"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3510" ref_id="CVE-2014-3510"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3511" ref_id="CVE-2014-3511"/>
        <description>[1.0.1e-34.4]
          - fix CVE-2014-3505 - doublefree in DTLS packet processing
          - fix CVE-2014-3506 - avoid memory exhaustion in DTLS
          - fix CVE-2014-3507 - avoid memory leak in DTLS
          - fix CVE-2014-3508 - fix OID handling to avoid information leak
          - fix CVE-2014-3509 - fix race condition when parsing server hello
          - fix CVE-2014-3510 - fix DoS in anonymous (EC)DH handling in DTLS
          - fix CVE-2014-3511 - disallow protocol downgrade via fragmentation</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:12.219-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:55.681-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:07.557-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126858 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:24.088-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:56.701-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.15" test_ref="oval:org.mitre.oval:tst:126663"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.15" test_ref="oval:org.mitre.oval:tst:126095"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.15" test_ref="oval:org.mitre.oval:tst:126863"/>
            <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.15" test_ref="oval:org.mitre.oval:tst:126808"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:126860"/>
            <criterion comment="openssl-devel is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:126520"/>
            <criterion comment="openssl-libs is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:126921"/>
            <criterion comment="openssl-perl is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:126858"/>
            <criterion comment="openssl-static is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:126776"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27228" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1038 -- tomcat6 security update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1038.html" ref_id="ELSA-2014-1038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0119" ref_id="CVE-2014-0119"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4590" ref_id="CVE-2013-4590"/>
        <description>[0:6.0.24-78]
        - Related: CVE-2013-4590  - remove xml schema names javaee_5,
        - javaee_web_services_1_2, and javaee_web_services_1_2_client
        - from descriptor.DigesterFactory initialization. These
        - schema definitions are not relevant to 6.0.24 as the version
        - of their spec did not exist at the time.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:14.390-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:54.768-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:07.065-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:126904"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:127003"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:126717"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:126634"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:126972"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:126676"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:126378"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:126707"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:126973"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27227" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3083 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3083.html" ref_id="ELSA-2014-3083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4653" ref_id="CVE-2014-4653"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4654" ref_id="CVE-2014-4654"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4655" ref_id="CVE-2014-4655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5077" ref_id="CVE-2014-5077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3122" ref_id="CVE-2014-3122"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2596" ref_id="CVE-2013-2596"/>
        <description>kernel-uek
        [2.6.32-400.36.9uek]
        - ALSA: control: Don't access controls outside of protected regions (Lars-Peter Clausen)  [Orabug: 19817787]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - ALSA: control: Fix replacing user controls (Lars-Peter Clausen)  [Orabug: 19817749]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - mm: try_to_unmap_cluster() should lock_page() before mlocking (Vlastimil Babka)  [Orabug: 19817324]  {CVE-2014-3122}
        - vm: convert fb_mmap to vm_iomap_memory() helper (Linus Torvalds)  [Orabug: 19816564]  {CVE-2013-2596}
        - vm: add vm_iomap_memory() helper function (Linus Torvalds)  [Orabug: 19816564]  {CVE-2013-2596}
        - net: sctp: inherit auth_capable on INIT collisions (Daniel Borkmann)  [Orabug: 19816069]  {CVE-2014-5077}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:08.273-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:53.829-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:06.658-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126513 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:26.871-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:08.920-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126748"/>
            <criterion comment="mlnx_en-2.6.32-400.36.9.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126651"/>
            <criterion comment="ofa-2.6.32-400.36.9.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126752"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126669"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126916"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126789"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126712"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126888"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.9.el5uek" test_ref="oval:org.mitre.oval:tst:126838"/>
            <criterion comment="mlnx_en-2.6.32-400.36.9.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126201"/>
            <criterion comment="ofa-2.6.32-400.36.9.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126513"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126521"/>
            <criterion comment="mlnx_en-2.6.32-400.36.9.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126839"/>
            <criterion comment="ofa-2.6.32-400.36.9.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126731"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126342"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126428"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126902"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126709"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126862"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.9.el6uek" test_ref="oval:org.mitre.oval:tst:126730"/>
            <criterion comment="mlnx_en-2.6.32-400.36.9.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126543"/>
            <criterion comment="ofa-2.6.32-400.36.9.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126821"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27226" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3053 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3053.html" ref_id="ELSA-2014-3053"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0196" ref_id="CVE-2014-0196"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3144" ref_id="CVE-2014-3144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3145" ref_id="CVE-2014-3145"/>
        <description>[2.6.39-400.215.6]
- filter: prevent nla extensions to peek beyond the end of the message (Mathias Krause)  [Orabug: 19315782]  {CVE-2014-3144} {CVE-2014-3145}

[2.6.39-400.215.5]
- n_tty: Fix n_tty_write crash when echoing in raw mode (Peter Hurley)  [Orabug: 18756449]  {CVE-2014-0196} {CVE-2014-0196}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:33.771-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:53.241-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:06.321-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:126203"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:127150"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:126819"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:126614"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:126818"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.6.el5uek" test_ref="oval:org.mitre.oval:tst:127153"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:126775"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:126609"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:126882"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:127106"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:127121"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.6.el6uek" test_ref="oval:org.mitre.oval:tst:126497"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27225" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1582 -- python security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1582.html" ref_id="ELSA-2013-1582"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4238" ref_id="CVE-2013-4238"/>
        <description>[2.6.6-51]
- Fixed memory leak in _ssl._get_peer_alt_names
Resolves: rhbz#1002983</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:30.488-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:52.940-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:06.166-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-11T15:56:04.267-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T15:56:04.267-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="python is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:128287"/>
          <criterion comment="python-devel is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:127982"/>
          <criterion comment="python-libs is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:127898"/>
          <criterion comment="python-test is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:128520"/>
          <criterion comment="python-tools is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:128236"/>
          <criterion comment="tkinter is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:128412"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27224" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1636 -- java-1.8.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.8.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1636.html" ref_id="ELSA-2014-1636"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6457" ref_id="CVE-2014-6457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6502" ref_id="CVE-2014-6502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6504" ref_id="CVE-2014-6504"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6506" ref_id="CVE-2014-6506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6511" ref_id="CVE-2014-6511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6512" ref_id="CVE-2014-6512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6517" ref_id="CVE-2014-6517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6519" ref_id="CVE-2014-6519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6531" ref_id="CVE-2014-6531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6558" ref_id="CVE-2014-6558"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6468" ref_id="CVE-2014-6468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6562" ref_id="CVE-2014-6562"/>
        <description>[1:1.8.0.25-1.b17]
        - Update to October CPU patch update.
        - Resolves: RHBZ#1148896</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:03.594-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:51.758-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:05.698-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.8.0-openjdk is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:126370"/>
          <criterion comment="java-1.8.0-openjdk-demo is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:126179"/>
          <criterion comment="java-1.8.0-openjdk-devel is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:126617"/>
          <criterion comment="java-1.8.0-openjdk-headless is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:126674"/>
          <criterion comment="java-1.8.0-openjdk-javadoc is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:126662"/>
          <criterion comment="java-1.8.0-openjdk-src is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:126365"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27223" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1823 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1823.html" ref_id="ELSA-2013-1823"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5609" ref_id="CVE-2013-5609"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5612" ref_id="CVE-2013-5612"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5613" ref_id="CVE-2013-5613"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5614" ref_id="CVE-2013-5614"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5616" ref_id="CVE-2013-5616"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5618" ref_id="CVE-2013-5618"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6671" ref_id="CVE-2013-6671"/>
        <description>[24.2.0-1.0.1.el6_5]

- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

- Make sure build with nspr-devel >= 4.10.0



[24.2.0-1]

- Update to 24.2.0 ESR



[24.1.0-1]

- Update to 24.1.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:50.398-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:51.093-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:05.430-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:19:20.019-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:19:20.019-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128335"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128150"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27222" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1418 -- kdelibs security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1418.html" ref_id="ELSA-2012-1418"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4513" ref_id="CVE-2012-4513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4512" ref_id="CVE-2012-4512"/>
        <description>[6:4.3.4-19.0.1]

- rebuild it with new rules

  add build requirement of installing libXdmcp-devel



[6:4.3.4-19]

- fix multilib conflict



[6:4.3.4-18]

- Resolves: bz#866230, CVE-2012-4512 CVE-2012-4513



[4.3.4-17]

- Resolves: bz#754161, bz#587016, bz#682611, bz#734734, bz#826114, respin



[6:4.3.4-16]

- Resolves: bz#754161, stop/warn when a subdir is not accessible when copying



[6:4.3.4-15]

- Resolves: bz#587016, print dialogue does not remember previous settings

- Resolves: bz#682611, Konqueror splash page in zh_TW is wrong

- Resolves: bz#734734, plasma eating up cpu-time when systemtray some icon

- Resolves: bz#826114, konqueror crash when trying to add 'Terminal Emulator' to main menu bar</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:15:03.118-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:50.816-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:05.264-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:18:33.227-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:18:33.227-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kdelibs is earlier than 0:4.3.4-19.0.1.el6" test_ref="oval:org.mitre.oval:tst:129641"/>
          <criterion comment="kdelibs-apidocs is earlier than 0:4.3.4-19.0.1.el6" test_ref="oval:org.mitre.oval:tst:129970"/>
          <criterion comment="kdelibs-common is earlier than 0:4.3.4-19.0.1.el6" test_ref="oval:org.mitre.oval:tst:129349"/>
          <criterion comment="kdelibs-devel is earlier than 0:4.3.4-19.0.1.el6" test_ref="oval:org.mitre.oval:tst:129930"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27219" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1829 -- nss, nspr, and nss-util security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1829.html" ref_id="ELSA-2013-1829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1739" ref_id="CVE-2013-1739"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1741" ref_id="CVE-2013-1741"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5605" ref_id="CVE-2013-5605"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5606" ref_id="CVE-2013-5606"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5607" ref_id="CVE-2013-5607"/>
        <description>nspr
[4.10.0-2]
- Rebase to nspr-4.10.2
- Resolves: rhbz#1032485 - CVE-2013-5607 (MFSA 2013-103) Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)

nss
[3.15.3-2.0.1]
- Added nss-vendor.patch to change vendor

[3.15.3-2]
- Enable patch with fix for deadlock in trust domain lock and object lock
- Resolves: Bug 1036477 - deadlock in trust domain lock and object lock
- Disable hw gcm on rhel-5 based build environments where OS lacks support
- Rollback changes to build nss without softokn until Bug 689919 is approved
- Cipher suite was run as part of the nss-softokn build

[3.15.3-1]
- Update to NSS_3_15_3_RTM
- Resolves: Bug 1032470 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741

nss-util
[3.15.3-1]
- Update to NSS_3_15_3_RTM
- Resolves: rhbz#1032470 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:40.576-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:49.884-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:04.780-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T10:59:13.638-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T10:59:13.638-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.10.2-1.el6_5" test_ref="oval:org.mitre.oval:tst:127406"/>
          <criterion comment="nss is earlier than 0:3.15.3-2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128231"/>
          <criterion comment="nss-util is earlier than 0:3.15.3-1.el6_5" test_ref="oval:org.mitre.oval:tst:128379"/>
          <criterion comment="nspr-devel is earlier than 0:4.10.2-1.el6_5" test_ref="oval:org.mitre.oval:tst:128319"/>
          <criterion comment="nss-devel is earlier than 0:3.15.3-2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128346"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127976"/>
          <criterion comment="nss-sysinit is earlier than 0:3.15.3-2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127828"/>
          <criterion comment="nss-tools is earlier than 0:3.15.3-2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128292"/>
          <criterion comment="nss-util-devel is earlier than 0:3.15.3-1.el6_5" test_ref="oval:org.mitre.oval:tst:127943"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27216" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2010-0945 -- quagga security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2010-0945.html" ref_id="ELSA-2010-0945"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2948" ref_id="CVE-2010-2948"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2949" ref_id="CVE-2010-2949"/>
        <description>[0.99.15-5_el6_0.1]
- Resolves: #644830 - CVE-2010-2948 CVE-2010-2949 quagga various flaws</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:48.429-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:49.369-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:04.427-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:53:59.624-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:53:59.624-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="quagga is earlier than 0:0.99.15-5.el6_0.1" test_ref="oval:org.mitre.oval:tst:134252"/>
          <criterion comment="quagga-contrib is earlier than 0:0.99.15-5.el6_0.1" test_ref="oval:org.mitre.oval:tst:134177"/>
          <criterion comment="quagga-devel is earlier than 0:0.99.15-5.el6_0.1" test_ref="oval:org.mitre.oval:tst:134267"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27215" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3069 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3069.html" ref_id="ELSA-2014-3069"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4667" ref_id="CVE-2014-4667"/>
        <description>kernel-uek
[2.6.32-400.36.7uek]
- sctp: Fix sk_ack_backlog wrap-around problem (Xufeng Zhang)  [Orabug: 19404246]  {CVE-2014-4667}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:06.731-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:49.127-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:04.206-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126584 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:24.885-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:08.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126764"/>
            <criterion comment="mlnx_en-2.6.32-400.36.7.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127021"/>
            <criterion comment="ofa-2.6.32-400.36.7.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126584"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126597"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:127016"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126577"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126783"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126529"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.7.el5uek" test_ref="oval:org.mitre.oval:tst:126685"/>
            <criterion comment="mlnx_en-2.6.32-400.36.7.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126837"/>
            <criterion comment="ofa-2.6.32-400.36.7.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126856"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126760"/>
            <criterion comment="mlnx_en-2.6.32-400.36.7.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126247"/>
            <criterion comment="ofa-2.6.32-400.36.7.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126758"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126980"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126832"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126920"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126679"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126873"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.7.el6uek" test_ref="oval:org.mitre.oval:tst:126028"/>
            <criterion comment="mlnx_en-2.6.32-400.36.7.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126417"/>
            <criterion comment="ofa-2.6.32-400.36.7.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126167"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27212" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1476 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1476.html" ref_id="ELSA-2013-1476"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5590" ref_id="CVE-2013-5590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5595" ref_id="CVE-2013-5595"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5597" ref_id="CVE-2013-5597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5599" ref_id="CVE-2013-5599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5600" ref_id="CVE-2013-5600"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5601" ref_id="CVE-2013-5601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5602" ref_id="CVE-2013-5602"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5604" ref_id="CVE-2013-5604"/>
        <description>firefox
[17.0.10-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one

[17.0.10-1]
- Update to 17.0.10 ESR

xulrunner
[17.0.10-1.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.10-1]
- Update to 17.0.10 ESR

[17.0.9-2]
- Added patch for rhbz#983488 - Resizing window changes window
  size to 0 with third party window manager.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:19.562-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:48.112-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:03.682-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:16:44.957-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:16:44.957-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.10-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128639"/>
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128750"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128741"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.10-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128559"/>
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128729"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:128727"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27211" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1591 -- openssh security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1591.html" ref_id="ELSA-2013-1591"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5107" ref_id="CVE-2010-5107"/>
        <description>[5.3p1-94]
- use dracut-fips package to determine if a FIPS module is installed (#1001565)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:44.023-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:47.929-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:03.568-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssh is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:128368"/>
          <criterion comment="openssh-askpass is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:128305"/>
          <criterion comment="openssh-clients is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:128489"/>
          <criterion comment="openssh-ldap is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:128478"/>
          <criterion comment="openssh-server is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:128500"/>
          <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9.3-94.el6" test_ref="oval:org.mitre.oval:tst:128347"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27208" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0185 -- openswan security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0185.html" ref_id="ELSA-2014-0185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6466" ref_id="CVE-2013-6466"/>
        <description>[2.6.32-27.2]
- Resolves: rhbz#1050337 (CVE-2013-6466 refix for delete/notify code)

[2.6.32-27.1]
- Resolves: rhbz#1050337 (CVE-2013-6466)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:28.149-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:47.739-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:03.423-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:39:21.029-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:39:21.029-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:127662"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:127960"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openswan is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:127971"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:127808"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27206" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0026 -- java-1.7.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0026.html" ref_id="ELSA-2014-0026"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5878" ref_id="CVE-2013-5878"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5884" ref_id="CVE-2013-5884"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5893" ref_id="CVE-2013-5893"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5896" ref_id="CVE-2013-5896"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5907" ref_id="CVE-2013-5907"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5910" ref_id="CVE-2013-5910"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0368" ref_id="CVE-2014-0368"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0373" ref_id="CVE-2014-0373"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0376" ref_id="CVE-2014-0376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0411" ref_id="CVE-2014-0411"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0416" ref_id="CVE-2014-0416"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0422" ref_id="CVE-2014-0422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0423" ref_id="CVE-2014-0423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0428" ref_id="CVE-2014-0428"/>
        <description>[1.7.0.51-2.4.4.1.0.1.el6_5]
- Update DISTRO_NAME in specfile

[1.7.0.51-2.4.4.1.el6]
- restored java7 provides
- bumped release (builds exists)
- Resolves: rhbz#1050935

[1.7.0.51-2.4.4.0.el6]
- updated to security icedtea 2.4.4
 - icedtea_version set to 2.4.4
 - updatever bumped to       51
 - release reset to 0
- sync with fedora
 - added and applied patch411 1029588.patch (rh 1029588)
 - added aand applied patch410, 1015432 (rh 1015432)
- Resolves: rhbz#1050935</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:38.190-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:46.595-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:02.828-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:42:54.643-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:42:54.643-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk is earlier than 0:1.7.0.51-2.4.4.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128183"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 0:1.7.0.51-2.4.4.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127778"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 0:1.7.0.51-2.4.4.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127956"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 0:1.7.0.51-2.4.4.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127284"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 0:1.7.0.51-2.4.4.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128042"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27203" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1270 -- polkit security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>polkit</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1270.html" ref_id="ELSA-2013-1270"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4288" ref_id="CVE-2013-4288"/>
        <description>[0.96-5]
- Actually apply the patch, and modify it to apply to 0.96
- Resolves: #1006262

[0.96-4.el6_4]
- Include fix for CVE-2013-4288
- Resolves: #1006262

[0.96-3.el6_4]
- Include fixes for CVE-2011-1485
- Resolves: #692942</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:03.431-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:45.975-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:02.319-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:00:13.295-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:00:13.295-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="polkit is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:128789"/>
          <criterion comment="polkit-desktop-policy is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:128983"/>
          <criterion comment="polkit-devel is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:129099"/>
          <criterion comment="polkit-docs is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:128739"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27200" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3046 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3046.html" ref_id="ELSA-2014-3046"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943" ref_id="CVE-2014-4943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4699" ref_id="CVE-2014-4699"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4348" ref_id="CVE-2013-4348"/>
        <description>kernel-uek
[3.8.13-35.1.3.el6uek]
- l2tp: fix an unprivileged user to kernel privilege escalation (Sasha Levin)  [Orabug: 19229497]  {CVE-2014-4943} {CVE-2014-4943}
- ptrace,x86: force IRET path after a ptrace_stop() (Tejun Heo)  [Orabug: 19230689]  {CVE-2014-4699}
- net: flow_dissector: fail on evil iph->ihl (Jason Wang)  [Orabug: 19231234]  {CVE-2013-4348}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:30.006-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:45.336-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:01.969-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27200 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:25.691-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:08.280-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-35.1.3.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:127291"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-35.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:127111"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-35.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:127342"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-35.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:127324"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-35.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:126846"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-35.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:127348"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-35.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:127259"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27197" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1012 -- php53 and php security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1012.html" ref_id="ELSA-2014-1012"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0237" ref_id="CVE-2014-0237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0238" ref_id="CVE-2014-0238"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3479" ref_id="CVE-2014-3479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3480" ref_id="CVE-2014-3480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3515" ref_id="CVE-2014-3515"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4049" ref_id="CVE-2014-4049"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4721" ref_id="CVE-2014-4721"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1571" ref_id="CVE-2012-1571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6712" ref_id="CVE-2013-6712"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1943" ref_id="CVE-2014-1943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2270" ref_id="CVE-2014-2270"/>
        <description>[5.3.3-27.1]
        - core: type confusion issue in phpinfo(). CVE-2014-4721
        - date: fix heap-based buffer over-read in DateInterval. CVE-2013-6712
        - core: fix heap-based buffer overflow in DNS TXT record parsing.
          CVE-2014-4049
        - core: unserialize() SPL ArrayObject / SPLObjectStorage type
          confusion flaw. CVE-2014-3515
        - fileinfo: out-of-bounds memory access in fileinfo. CVE-2014-2270
        - fileinfo: unrestricted recursion in handling of indirect type
          rules. CVE-2014-1943
        - fileinfo: out of bounds read in CDF parser. CVE-2012-1571
        - fileinfo: cdf_check_stream_offset boundary check. CVE-2014-3479
        - fileinfo: cdf_count_chain insufficient boundary check. CVE-2014-3480
        - fileinfo: cdf_unpack_summary_info() excessive looping
          DoS. CVE-2014-0237
        - fileinfo: CDF property info parsing nelements infinite
          loop. CVE-2014-0238</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:10.403-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:44.222-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:01.447-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126976"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126968"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126875"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126791"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126884"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126282"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126954"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:127004"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126678"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126642"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:127060"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126425"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126948"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126774"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126656"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126841"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126404"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126870"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126816"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:127001"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:126988"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126705"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126847"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127002"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127030"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126895"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126525"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126865"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126989"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126990"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127057"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126767"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126581"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127008"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126455"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127061"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126698"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126583"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127041"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126606"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126840"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126956"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126316"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126753"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126400"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126608"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:126174"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:127049"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27196" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0731 -- expat security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>expat</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0731.html" ref_id="ELSA-2012-0731"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0876" ref_id="CVE-2012-0876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1148" ref_id="CVE-2012-1148"/>
        <description>[2.0.1-11]
- use symbol version for XML_SetHashSalt (CVE-2012-0876, #816306)

[2.0.1-10]
- add security fix for CVE-2012-1148 (#811825)
- add security fix for CVE-2012-0876 (#811833)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:10.566-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:43.967-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:01.316-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:23:55.226-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:23:55.226-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="expat is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:131762"/>
            <criterion comment="expat-devel is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:131276"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="expat is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:131948"/>
            <criterion comment="expat-devel is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:131949"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27195" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0414 -- policycoreutils security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>policycoreutils</product>
          <product>selinux-policy</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0414.html" ref_id="ELSA-2011-0414"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1011" ref_id="CVE-2011-1011"/>
        <description>policycoreutils:

[2.0.83-19.8]
- Fix seunshare to work with /tmp content when SELinux context is not provided
Resolves: #679689

[2.0.83-19.7]
- put back correct chcon
- Latest fixes for seunshare

[2.0.83-19.6]
- Fix rsync command to work if the directory is old.
- Fix all tests
Resolves: #679689

[2.0.83-19.5]
- Add requires rsync and  fix man page for seunshare

[2.0.83-19.4]
- fix to sandbox
  - Fix seunshare to use more secure handling of /tmp
    - Rewrite seunshare to make sure /tmp is mounted stickybit owned by root
   - Change to allow sandbox to run on nfs homedirs, add start python script
   - change default location of HOMEDIR in sandbox to /tmp/.sandbox_home_*
   - Move seunshare to sandbox package
   - Fix sandbox to show correct types in  usage statement

selinux-policy:

[3.7.19-54.0.1.el6_0.5]
- Allow ocfs2 to be mounted with file_t type.

[3.7.19-54.el6_0.5]
- seunshare needs to be able to mounton nfs/cifs/fusefs homedirs
Resolves: #684918

[3.7.19-54.el6_0.4]
- Fix to sandbox
        * selinux-policy fixes for policycoreutils sandbox changes
                - Fix seunshare to use more secure handling of /tmp
                - Change to allow sandbox to run on nfs homedirs, add start python script</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T19:01:56.635-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:43.498-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:01.103-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:21:29.222-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:21:29.222-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="policycoreutils is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:134021"/>
          <criterion comment="selinux-policy is earlier than 0:3.7.19-54.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133520"/>
          <criterion comment="policycoreutils-gui is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:133950"/>
          <criterion comment="policycoreutils-newrole is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:133955"/>
          <criterion comment="policycoreutils-python is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:133175"/>
          <criterion comment="policycoreutils-sandbox is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:133935"/>
          <criterion comment="selinux-policy-doc is earlier than 0:3.7.19-54.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133588"/>
          <criterion comment="selinux-policy-minimum is earlier than 0:3.7.19-54.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:134164"/>
          <criterion comment="selinux-policy-mls is earlier than 0:3.7.19-54.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133727"/>
          <criterion comment="selinux-policy-targeted is earlier than 0:3.7.19-54.0.1.el6_0.5" test_ref="oval:org.mitre.oval:tst:133892"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27192" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1110 -- glibc security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1110.html" ref_id="ELSA-2014-1110"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0475" ref_id="CVE-2014-0475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119" ref_id="CVE-2014-5119"/>
        <description>An off-by-one heap-based buffer overflow flaw was found in glibc's internal
          __gconv_translit_find() function. An attacker able to make an application
          call the iconv_open() function with a specially crafted argument could
          possibly use this flaw to execute arbitrary code with the privileges of
          that application. (CVE-2014-5119)

          A directory traveral flaw was found in the way glibc loaded locale files.
          An attacker able to make an application use a specially crafted locale name
          value (for example, specified in an LC_* environment variable) could
          possibly use this flaw to execute arbitrary code with the privileges of
          that application. (CVE-2014-0475)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:27.598-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:40.605-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:01:00.004-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126987"/>
            <criterion comment="glibc-common is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126587"/>
            <criterion comment="glibc-devel is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126668"/>
            <criterion comment="glibc-headers is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126358"/>
            <criterion comment="glibc-utils is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126898"/>
            <criterion comment="nscd is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:126586"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126330"/>
            <criterion comment="glibc-common is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126983"/>
            <criterion comment="glibc-devel is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126239"/>
            <criterion comment="glibc-headers is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126649"/>
            <criterion comment="glibc-static is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126715"/>
            <criterion comment="glibc-utils is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126951"/>
            <criterion comment="nscd is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:126479"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27188" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1605 -- glibc security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1605.html" ref_id="ELSA-2013-1605"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0242" ref_id="CVE-2013-0242"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1914" ref_id="CVE-2013-1914"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4332" ref_id="CVE-2013-4332"/>
        <description>[2.12-1.132] 

- Revert the addition of gettimeofday vDSO function for ppc and ppc64 until 

OPD VDSO function call issues are resolved (#1026533).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:46.000-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:39.903-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:59.671-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:128011"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:128582"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:128609"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:128221"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:128651"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:128472"/>
          <criterion comment="nscd is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:128665"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27186" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1123 -- bind security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1123.html" ref_id="ELSA-2012-1123"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3817" ref_id="CVE-2012-3817"/>
        <description>[32:9.8.2-0.10.rc1.2]
- fix CVE-2012-3817</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:20.427-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:39.635-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:59.507-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T15:08:38.406-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T15:08:38.406-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:130891"/>
            <criterion comment="bind-chroot is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:130911"/>
            <criterion comment="bind-devel is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131404"/>
            <criterion comment="bind-libbind-devel is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131385"/>
            <criterion comment="bind-libs is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131376"/>
            <criterion comment="bind-sdb is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:130568"/>
            <criterion comment="bind-utils is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131294"/>
            <criterion comment="caching-nameserver is earlier than 0:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:131468"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131251"/>
            <criterion comment="bind-chroot is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131277"/>
            <criterion comment="bind-devel is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131557"/>
            <criterion comment="bind-libs is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131058"/>
            <criterion comment="bind-sdb is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131545"/>
            <criterion comment="bind-utils is earlier than 0:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:131456"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27184" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0981 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0981.html" ref_id="ELSA-2014-0981"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2851" ref_id="CVE-2014-2851"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7339" ref_id="CVE-2013-7339"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3144" ref_id="CVE-2014-3144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3145" ref_id="CVE-2014-3145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2678" ref_id="CVE-2014-2678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6647" ref_id="CVE-2012-6647"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2672" ref_id="CVE-2014-2672"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2706" ref_id="CVE-2014-2706"/>
        <description>[2.6.32-431.23.3]
- [netdrv] pppol2tp: fail when socket option level is not SOL_PPPOL2TP [1119461 1119462] {CVE-2014-4943}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:35.624-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:38.737-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:59.070-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:127162"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:127102"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:127078"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:126477"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:127158"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:126756"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:127109"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:127131"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:126420"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:127079"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27181" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-0534 -- qemu-kvm security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-0534.html" ref_id="ELSA-2011-0534"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1750" ref_id="CVE-2011-1750"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1751" ref_id="CVE-2011-1751"/>
        <description>It was found that the virtio-blk driver in qemu-kvm did not properly
validate read and write requests from guests. A privileged guest user could
use this flaw to crash the guest or, possibly, execute arbitrary code on
the host.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:39">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:58:34.304-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:38.460-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:58.890-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T20:19:20.584-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T20:19:20.584-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.160.el6" test_ref="oval:org.mitre.oval:tst:133939"/>
          <criterion comment="qemu-img is earlier than 0:0.12.1.2-2.160.el6" test_ref="oval:org.mitre.oval:tst:133750"/>
          <criterion comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.160.el6" test_ref="oval:org.mitre.oval:tst:133673"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27180" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0748 -- libvirt security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0748.html" ref_id="ELSA-2012-0748"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2693" ref_id="CVE-2012-2693"/>
        <description>[libvirt-0.9.10-21.0.1.el6]
- Replace docs/et.png in tarball with blank image

[libvirt-0.9.10-21.el6]
- qemu: Rollback on used USB devices (rhbz#743671)
- qemu: Dont delete USB device on failed qemuPrepareHostdevUSBDevices (rhbz#743671)
- Revert 'rpc: Discard non-blocking calls only when necessary' (rhbz#821468)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:19.419-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:38.295-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:58.746-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:07:56.856-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:07:56.856-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.9.10-21.0.1.el6" test_ref="oval:org.mitre.oval:tst:131689"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.0.1.el6" test_ref="oval:org.mitre.oval:tst:131348"/>
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.0.1.el6" test_ref="oval:org.mitre.oval:tst:131425"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.9.10-21.0.1.el6" test_ref="oval:org.mitre.oval:tst:131707"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.0.1.el6" test_ref="oval:org.mitre.oval:tst:131500"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27177" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1457 -- libgcrypt security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libgcrypt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1457.html" ref_id="ELSA-2013-1457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4242" ref_id="CVE-2013-4242"/>
        <description>[1.4.5-11]
- fix CVE-2013-4242 GnuPG/libgcrypt susceptible to cache side-channel attack

[1.4.5-10]
- Add GCRYCTL_SET_ENFORCED_FIPS_FLAG command</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:16.685-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:37.910-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:58.240-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:50:31.348-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:50:31.348-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libgcrypt is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:128783"/>
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:128802"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libgcrypt is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:128691"/>
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:128806"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27169" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011-1790 -- krb5 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2011-1790.html" ref_id="ELSA-2011-1790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1530" ref_id="CVE-2011-1530"/>
        <description>[1.9-22.1]
- add candidate patch to fix a NULL pointer dereference while processing TGS
  requests (MITKRB5-SA-2011-007, #754046)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:23">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:53:27.051-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:36.621-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:57.455-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:38:00.412-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:38:00.412-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:132854"/>
          <criterion comment="krb5-devel is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:133097"/>
          <criterion comment="krb5-libs is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:132834"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:133000"/>
          <criterion comment="krb5-server is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:133006"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:132980"/>
          <criterion comment="krb5-workstation is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:132915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27165" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0568 -- dbus-glib security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>dbus-glib</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0568.html" ref_id="ELSA-2013-0568"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0292" ref_id="CVE-2013-0292"/>
        <description>[0.73-11]

- Add patch to fix CVE-2013-0292

- Resolves: #913072</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:48.490-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:36.228-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:57.045-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:19:37.768-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:19:37.768-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus-glib is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:130294"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:130165"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:129651"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:130093"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27161" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0387 -- firefox security and bug fix update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0387.html" ref_id="ELSA-2012-0387"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0451" ref_id="CVE-2012-0451"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0455" ref_id="CVE-2012-0455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0456" ref_id="CVE-2012-0456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0457" ref_id="CVE-2012-0457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0458" ref_id="CVE-2012-0458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0459" ref_id="CVE-2012-0459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0460" ref_id="CVE-2012-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0461" ref_id="CVE-2012-0461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0462" ref_id="CVE-2012-0462"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0464" ref_id="CVE-2012-0464"/>
        <description>firefox:

[10.0.3-1.0.1.el6_2]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[10.0.3-1]
- Update to 10.0.3 ESR

xulrunner:

[10.0.3-1.0.1.el6_2]
- Replace xulrunner-redhat-default-prefs.js with
- xulrunner-oracle-default-prefs.js

[10.0.3-1]
- Update to 10.0.3 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:19.969-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:35.190-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:56.438-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:03:16.869-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:03:16.869-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.3-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132321"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132434"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:132495"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.3-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132278"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132431"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.0.1.el6_2" test_ref="oval:org.mitre.oval:tst:132350"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27158" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3054 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3054.html" ref_id="ELSA-2014-3054"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0196" ref_id="CVE-2014-0196"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3144" ref_id="CVE-2014-3144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3145" ref_id="CVE-2014-3145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6647" ref_id="CVE-2012-6647"/>
        <description>kernel-uek
[2.6.32-400.36.6uek]
- filter: prevent nla extensions to peek beyond the end of the message (Mathias Krause)  [Orabug: 19315783]  {CVE-2014-3144} {CVE-2014-3145}
- futex: Forbid uaddr == uaddr2 in futex_wait_requeue_pi() (Darren Hart)  [Orabug: 19315318]  {CVE-2012-6647}

[2.6.32-400.36.5uek]
- n_tty: Fix n_tty_write crash when echoing in raw mode (Peter Hurley)  [Orabug: 18756450]  {CVE-2014-0196} {CVE-2014-0196}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:13.186-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:33.205-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:55.523-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127137 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:27.200-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:07.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:126978"/>
            <criterion comment="mlnx_en-2.6.32-400.36.6.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127039"/>
            <criterion comment="ofa-2.6.32-400.36.6.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126658"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:127042"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:126906"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:127099"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:127143"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:126348"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.6.el5uek" test_ref="oval:org.mitre.oval:tst:126631"/>
            <criterion comment="mlnx_en-2.6.32-400.36.6.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127075"/>
            <criterion comment="ofa-2.6.32-400.36.6.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127137"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:126628"/>
            <criterion comment="mlnx_en-2.6.32-400.36.6.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127157"/>
            <criterion comment="ofa-2.6.32-400.36.6.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126779"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:127126"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:126382"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:126770"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:127069"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:127033"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.6.el6uek" test_ref="oval:org.mitre.oval:tst:126930"/>
            <criterion comment="mlnx_en-2.6.32-400.36.6.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126891"/>
            <criterion comment="ofa-2.6.32-400.36.6.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27154" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1803 -- libjpeg-turbo security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libjpeg-turbo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1803.html" ref_id="ELSA-2013-1803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6629" ref_id="CVE-2013-6629"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6630" ref_id="CVE-2013-6630"/>
        <description>[1.2.1-3]
- Resolves: #1031955 apply patch for CVE-2013-6630

[1.2.1-2]
- Resolves: #1031955 libjpeg-turbo: various flaws (CVE-2013-6629)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:40.966-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:32.703-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:55.399-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:41:32.927-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:41:32.927-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libjpeg-turbo is earlier than 0:1.2.1-3.el6_5" test_ref="oval:org.mitre.oval:tst:128059"/>
          <criterion comment="libjpeg-turbo-devel is earlier than 0:1.2.1-3.el6_5" test_ref="oval:org.mitre.oval:tst:127908"/>
          <criterion comment="libjpeg-turbo-static is earlier than 0:1.2.1-3.el6_5" test_ref="oval:org.mitre.oval:tst:128393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27151" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0625 -- openssl security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0625.html" ref_id="ELSA-2014-0625"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5298" ref_id="CVE-2010-5298"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0195" ref_id="CVE-2014-0195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0198" ref_id="CVE-2014-0198"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0221" ref_id="CVE-2014-0221"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224" ref_id="CVE-2014-0224"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3470" ref_id="CVE-2014-3470"/>
        <description>[1.0.1e-16.14]
- fix CVE-2010-5298 - possible use of memory after free
- fix CVE-2014-0195 - buffer overflow via invalid DTLS fragment
- fix CVE-2014-0198 - possible NULL pointer dereference
- fix CVE-2014-0221 - DoS from invalid DTLS handshake packet
- fix CVE-2014-0224 - SSL/TLS MITM vulnerability
- fix CVE-2014-3470 - client-side DoS when using anonymous ECDH</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:22.778-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:32.061-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:55.283-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:43:37.481-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:43:37.481-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:127252"/>
          <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:127282"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:127332"/>
          <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:127462"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27145" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0663 -- sssd security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0663.html" ref_id="ELSA-2013-0663"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0287" ref_id="CVE-2013-0287"/>
        <description>[1.9.2-82.4]
- Resolves: rhbz#911298 - sssd: simple access provider flaw prevents intended
                           ACL use when client to an AD provider

[1.9.2-82.3]
- Fix pwd_expiration_warning=0
- Resolves: rhbz#914671 - pwd_expiration_warning has wrong default for
                          Kerberos

[1.9.2-82.2]
- Resolves: rhbz#914671 - pwd_expiration_warning has wrong default for
                          Kerberos
- Fix the NVR

[1.9.2-82.1]
- Resolves: rhbz#907362 - Serious performance regression in sssd</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:39.024-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:30.346-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:54.881-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:39:04.473-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:39:04.473-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="sssd is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129820"/>
          <criterion comment="libipa_hbac is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129945"/>
          <criterion comment="libipa_hbac-devel is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129903"/>
          <criterion comment="libipa_hbac-python is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129594"/>
          <criterion comment="libsss_autofs is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129838"/>
          <criterion comment="libsss_idmap is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129726"/>
          <criterion comment="libsss_idmap-devel is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129802"/>
          <criterion comment="libsss_sudo is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129912"/>
          <criterion comment="libsss_sudo-devel is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129716"/>
          <criterion comment="sssd-client is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129893"/>
          <criterion comment="sssd-tools is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:129822"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27142" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0656 -- krb5 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0656.html" ref_id="ELSA-2013-0656"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1016" ref_id="CVE-2012-1016"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1415" ref_id="CVE-2013-1415"/>
        <description>[1.10.3-10.1]
- incorporate upstream patch to fix a NULL pointer dereference when the client
  supplies an otherwise-normal-looking PKINIT request (CVE-2013-1415, #917909)
- add patch to avoid dereferencing a NULL pointer in the KDC when handling a
  draft9 PKINIT request (#917909, CVE-2012-1016)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:47.226-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:29.217-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:54.639-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:32:24.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:32:24.044-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129897"/>
          <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129902"/>
          <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129469"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129164"/>
          <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129435"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129564"/>
          <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:129765"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27141" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0889 -- java-1.7.0-openjdk security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0889.html" ref_id="ELSA-2014-0889"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2483" ref_id="CVE-2014-2483"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2490" ref_id="CVE-2014-2490"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4209" ref_id="CVE-2014-4209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4216" ref_id="CVE-2014-4216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4218" ref_id="CVE-2014-4218"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4219" ref_id="CVE-2014-4219"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4221" ref_id="CVE-2014-4221"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4223" ref_id="CVE-2014-4223"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4244" ref_id="CVE-2014-4244"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4252" ref_id="CVE-2014-4252"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4262" ref_id="CVE-2014-4262"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4263" ref_id="CVE-2014-4263"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4266" ref_id="CVE-2014-4266"/>
        <description>[1.7.0.65-2.5.1.2.0.1.el6_5]
- Update DISTRO_NAME in specfile

[1.7.0.65-2.5.1.2]
- added and applied fix for samrtcard io patch405, pr1864_smartcardIO.patch
- Resolves: rhbz#1115874

[1.7.0.65-2.5.1.1.el6]
- updated to security patched icedtea7-forest 2.5.1
- Resolves: rhbz#1115874

[1.7.0.60-2.5.0.1.el6]
- update to icedtea7-forest 2.5.0
- Resolves: rhbz#1115874</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:12.444-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:28.011-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:53.931-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127242 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:42.036-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:30.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127210"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:126966"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127052"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:126726"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:126777"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:127242"/>
            <criterion comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.65-2.5.1.2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:127389"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:127083"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:127402"/>
            <criterion comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.65-2.5.1.2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126765"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:127360"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:127281"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27136" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3082 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3082.html" ref_id="ELSA-2014-3082"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4653" ref_id="CVE-2014-4653"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4654" ref_id="CVE-2014-4654"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4655" ref_id="CVE-2014-4655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5077" ref_id="CVE-2014-5077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3601" ref_id="CVE-2014-3601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3122" ref_id="CVE-2014-3122"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2596" ref_id="CVE-2013-2596"/>
        <description>[2.6.39-400.215.11]
        - ALSA: control: Don't access controls outside of protected regions (Lars-Peter Clausen)  [Orabug: 19817786]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - ALSA: control: Fix replacing user controls (Lars-Peter Clausen)  [Orabug: 19817748]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - kvm: iommu: fix the third parameter of kvm_iommu_put_pages (CVE-2014-3601) (Michael S. Tsirkin)  [Orabug: 19817647]  {CVE-2014-3601}
        - mm: try_to_unmap_cluster() should lock_page() before mlocking (Vlastimil Babka)  [Orabug: 19817323]  {CVE-2014-3122}
        - vm: convert fb_mmap to vm_iomap_memory() helper (Linus Torvalds)  [Orabug: 19816563]  {CVE-2013-2596}
        - vm: add vm_iomap_memory() helper function (Linus Torvalds)  [Orabug: 19816563]  {CVE-2013-2596}
        - net: sctp: inherit auth_capable on INIT collisions (Daniel Borkmann)  [Orabug: 19816068]  {CVE-2014-5077}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:26.722-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:26.218-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:53.186-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126675"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126811"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126647"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126741"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126927"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.11.el5uek" test_ref="oval:org.mitre.oval:tst:126672"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126708"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126750"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126845"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126526"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126424"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.11.el6uek" test_ref="oval:org.mitre.oval:tst:126876"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27134" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1635 -- firefox security update</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>xulrunner-devel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1635.html" ref_id="ELSA-2014-1635"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1574" ref_id="CVE-2014-1574"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1576" ref_id="CVE-2014-1576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1577" ref_id="CVE-2014-1577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1578" ref_id="CVE-2014-1578"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1581" ref_id="CVE-2014-1581"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1583" ref_id="CVE-2014-1583"/>
        <description>firefox
[31.2.0-3.0.1.el7_0]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat one

[31.2.0-3]
- Update to 31.2.0 ESR
- Fix for mozbz#1042889

[31.1.0-7]
- Enable WebM on all arches

xulrunner
[31.2.0-1.0.1]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[31.2.0-1]
- Update to 31.2.0

[31.1.0-3]
- move /sdk/bin to xulrunner libdir

[31.1.0-2]
- Sync preferences with Firefox package

[31.1.0-1]
- Update to 31.1.0 ESR

[31.0-2]
- Fix header wrapper for aarch64

[31.0-1]
- Update to 31.0 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:15.310-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27134 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:47.416-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:38.154-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:31.2.0-3.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126202"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox is earlier than 0:31.2.0-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:125364"/>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:31.2.0-3.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126173"/>
            <criterion comment="xulrunner is earlier than 0:31.2.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126222"/>
            <criterion comment="xulrunner-devel is earlier than 0:31.2.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27133" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1512 -- libxml2 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1512.html" ref_id="ELSA-2012-1512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5134" ref_id="CVE-2012-5134"/>
        <description>[2.7.6-8.0.1.el6_3.4 ]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball

[2.7.6-8.el6_3.4]
- fix out of range heap access (CVE-2012-5134)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:46.413-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:25.769-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:52.857-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:26:15.530-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:26:15.530-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.0.1.el5_8.6" test_ref="oval:org.mitre.oval:tst:130537"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.0.1.el5_8.6" test_ref="oval:org.mitre.oval:tst:130705"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.0.1.el5_8.6" test_ref="oval:org.mitre.oval:tst:130152"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130357"/>
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130386"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130674"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.0.1.el6_3.4" test_ref="oval:org.mitre.oval:tst:130385"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27132" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0595 -- gnutls security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0595.html" ref_id="ELSA-2014-0595"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3466" ref_id="CVE-2014-3466"/>
        <description>[2.8.5-14]
- fix session ID length check (#1102024)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:39.438-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:25.323-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:52.675-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:41:18.430-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:41:18.430-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gnutls is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:127383"/>
          <criterion comment="gnutls-devel is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:127625"/>
          <criterion comment="gnutls-guile is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:126743"/>
          <criterion comment="gnutls-utils is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:127624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27131" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0043 -- bind security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0043.html" ref_id="ELSA-2014-0043"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0591" ref_id="CVE-2014-0591"/>
        <description>[32:9.8.2-0.23.rc1.1]
- Fix CVE-2014-0591

[32:9.8.2-0.23.rc1]
- Fix gssapictx memory leak (#911167)

[32:9.8.2-0.22.rc1]
- fix CVE-2013-4854

[32:9.8.2-0.21.rc1]
- fix  CVE-2013-2266
- ship dns/rrl.h in -devel subpkg

[32:9.8.2-0.20.rc1]
- remove one bogus file from /usr/share/doc, introduced by RRL patch

[32:9.8.2-0.19.rc1]
- fix CVE-2012-5689

[32:9.8.2-0.18.rc1]
- add response rate limit patch (#873624)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:37.385-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:25.025-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:52.458-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127776 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:26.339-05:00">INTERIM</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:09:53.018-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:09:53.018-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bind is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127239"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127691"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127776"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:128092"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127832"/>
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:128192"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27130" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0626 -- openssl097a and openssl098e security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0626.html" ref_id="ELSA-2014-0626"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224" ref_id="CVE-2014-0224"/>
        <description>[0.9.8e-18.0.1.el6_5.2]
- Updated the description

[0.9.8e-18.2]
- fix for CVE-2014-0224 - SSL/TLS MITM vulnerability

[0.9.8e-18]
- fix for CVE-2012-2110 - memory corruption in asn1_d2i_read_bio() (#814185)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:38.453-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:24.759-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:52.334-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:45:19.767-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:45:19.767-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="openssl097a is earlier than 0:0.9.7a-12.el5_10.1" test_ref="oval:org.mitre.oval:tst:127483"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="openssl098e is earlier than 0:0.9.8e-18.0.1.el6_5.2" test_ref="oval:org.mitre.oval:tst:127613"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27126" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1407 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1407.html" ref_id="ELSA-2012-1407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4194" ref_id="CVE-2012-4194"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4195" ref_id="CVE-2012-4195"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4196" ref_id="CVE-2012-4196"/>
        <description>firefox
[10.0.10-1.0.1.el6_3]
- Replaced firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.10-1]
- Update to 10.0.10 ESR

[10.0.8-2]
- Fixed rhbz#865284 - add the storage.nfs_filesystem
  config key to property list
- disable OOP for wrapped plugins (nspluginwrapper)

xulrunner
[10.0.10-1.0.1.el6_3]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.10-1]
- Added patches from 10.0.10 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:40.629-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:22.631-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:52.126-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:54:48.119-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:54:48.119-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.10-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130508"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130740"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130883"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.10-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130979"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130473"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130695"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27121" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1606 -- file security and bug fix update</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>file</product>
          <product>file-devel</product>
          <product>file-libs</product>
          <product>file-static</product>
          <product>python-magic</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1606.html" ref_id="ELSA-2014-1606"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0237" ref_id="CVE-2014-0237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0238" ref_id="CVE-2014-0238"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3479" ref_id="CVE-2014-3479"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3480" ref_id="CVE-2014-3480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1571" ref_id="CVE-2012-1571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1943" ref_id="CVE-2014-1943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2270" ref_id="CVE-2014-2270"/>
        <description>[5.04-21]
- fix typographical error in changelog

[5.04-20]
- fix #1037279 - better patch for the bug from previous release

[5.04-19]
- fix #1037279 - display 'from' field on 32bit ppc core

[5.04-18]
- fix #664513 - trim white-spaces during ISO9660 detection

[5.04-17]
- fix CVE-2014-3479 (cdf_check_stream_offset boundary check)
- fix CVE-2014-3480 (cdf_count_chain insufficient boundary check)
- fix CVE-2014-0237 (cdf_unpack_summary_info() excessive looping DoS)
- fix CVE-2014-0238 (CDF property info parsing nelements infinite loop)
- fix CVE-2014-2270 (out-of-bounds access in search rules with offsets)
- fix CVE-2014-1943 (unrestricted recursion in handling of indirect type rules)
- fix CVE-2012-1571 (out of bounds read in CDF parser)

[5.04-16]
- fix #873997 - improve Minix detection pattern to fix false positives
- fix #884396 - improve PBM pattern to fix misdetection with x86 boot sector
- fix #980941 - improve Bio-Rad pattern to fix false positives
- fix #849621 - tweak strength of XML, Latex and Python patterns to execute
  them in the proper order
- fix #1067771 - detect qcow version 3 images
- fix #1064463 - treat RRDTool files as binary files</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:20:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:16.048-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27121 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:46.409-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:37.664-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="file is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:126337"/>
          <criterion comment="file-devel is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:126164"/>
          <criterion comment="file-libs is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:126311"/>
          <criterion comment="file-static is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:126283"/>
          <criterion comment="python-magic is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:126295"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27119" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1507 -- trousers security, bug fix, and enhancement update</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>trousers</product>
          <product>trousers-devel</product>
          <product>trousers-static</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1507.html" ref_id="ELSA-2014-1507"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0698" ref_id="CVE-2012-0698"/>
        <description>[0.3.13-2]
- Fix strict alias warning

[0.3.13-1]
- New upstream bug fix release
resolves: #633584 - Pick up latest TrouSerS package
resolves: #1074634 - Buffer overflow detected in TrouSerS daemon</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:13.179-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27119 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:45.827-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:37.337-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="trousers is earlier than 0:0.3.13-2.el6" test_ref="oval:org.mitre.oval:tst:125534"/>
          <criterion comment="trousers-devel is earlier than 0:0.3.13-2.el6" test_ref="oval:org.mitre.oval:tst:126118"/>
          <criterion comment="trousers-static is earlier than 0:0.3.13-2.el6" test_ref="oval:org.mitre.oval:tst:125981"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27118" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1306 -- bash security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1306.html" ref_id="ELSA-2014-1306"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7169" ref_id="CVE-2014-7169"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7186" ref_id="CVE-2014-7186"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7187" ref_id="CVE-2014-7187"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271" ref_id="CVE-2014-6271"/>
        <description>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

It was found that the fix for CVE-2014-6271 was incomplete, and Bash still
allowed certain characters to be injected into other environments via
specially crafted environment variables. An attacker could potentially use
this flaw to override or bypass environment restrictions to execute shell
commands. Certain services and applications allow remote unauthenticated
attackers to provide environment variables, allowing them to exploit this
issue. (CVE-2014-7169)

Applications which directly create bash functions as environment variables
need to be made aware of changes to the way names are handled by this
update. Note that certain services, screen sessions, and tmux sessions may
need to be restarted, and affected interactive users may need to re-login.
Installing these updated packages without restarting services will address
the vulnerability, but functionality may be impacted until affected
services are restarted. For more information see the Knowledgebase article
at &lt;A HREF="https://access.redhat.com/articles/1200223">https://access.redhat.com/articles/1200223&lt;/A>

Note: Docker users are advised to use &amp;quot;yum update&amp;quot; within their containers,
and to commit the resulting changes.

For additional information on CVE-2014-6271 and CVE-2014-7169, refer to the
aforementioned Knowledgebase article.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:30.153-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:53.905-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:45.088-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bash RPM is earlier than 0:4.2.45-5.el7_0.4" test_ref="oval:org.mitre.oval:tst:124970"/>
            <criterion comment="bash-doc RPM is earlier than 0:4.2.45-5.el7_0.4" test_ref="oval:org.mitre.oval:tst:124279"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bash RPM is earlier than 0:4.1.2-15.el6_5.2" test_ref="oval:org.mitre.oval:tst:124960"/>
            <criterion comment="bash-doc RPM is earlier than 0:4.1.2-15.el6_5.2" test_ref="oval:org.mitre.oval:tst:124908"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="bash RPM is earlier than 0:3.2-33.el5_11.4" test_ref="oval:org.mitre.oval:tst:124880"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27117" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0917 -- nss and nspr security, bug fix, and enhancement update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0917.html" ref_id="ELSA-2014-0917"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1740" ref_id="CVE-2013-1740"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1490" ref_id="CVE-2014-1490"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1491" ref_id="CVE-2014-1491"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1492" ref_id="CVE-2014-1492"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1544" ref_id="CVE-2014-1544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1545" ref_id="CVE-2014-1545"/>
        <description>nspr
[4.10.6-1]
- Rebase to nspr-4.10.6
- Resolves: rhbz#1112135

nss
[3.16.1-4.0.1.el6_5]
- Added nss-vendor.patch to change vendor

[3.16.1-4]
- Update some patches on account of the rebase
- Resolves: Bug 1099619

[3.16.1-3]
- Backport nss-3.12.6 upstream fix required by Firefox 31
- Resolves: Bug 1099619

[3.16.1-2]
- Remove two unused patches and apply a needed one that was missed
- Resolves: Bug 1112136 - Rebase nss in RHEL 6.5.Z to NSS 3.16.1

[3.16.1-1]
- Update to nss-3.16.1
- Resolves: Bug 1112136 - Rebase nss in RHEL 6.5.Z to NSS 3.16.1

nss-util
[3.15.6-1]
- Update to nss-3.16.1
- Resolves: rhbz#1112136</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:17.257-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:19.377-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:51.360-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nspr is earlier than 0:4.10.6-1.el6_5" test_ref="oval:org.mitre.oval:tst:127123"/>
          <criterion comment="nss is earlier than 0:3.16.1-4.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127322"/>
          <criterion comment="nss-util is earlier than 0:3.16.1-1.el6_5" test_ref="oval:org.mitre.oval:tst:126612"/>
          <criterion comment="nspr-devel is earlier than 0:4.10.6-1.el6_5" test_ref="oval:org.mitre.oval:tst:126786"/>
          <criterion comment="nss-devel is earlier than 0:3.16.1-4.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127227"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.1-4.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127184"/>
          <criterion comment="nss-sysinit is earlier than 0:3.16.1-4.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:126929"/>
          <criterion comment="nss-tools is earlier than 0:3.16.1-4.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127384"/>
          <criterion comment="nss-util-devel is earlier than 0:3.16.1-1.el6_5" test_ref="oval:org.mitre.oval:tst:127301"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27116" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1089 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1089.html" ref_id="ELSA-2012-1089"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1948" ref_id="CVE-2012-1948"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1951" ref_id="CVE-2012-1951"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1952" ref_id="CVE-2012-1952"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1953" ref_id="CVE-2012-1953"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1954" ref_id="CVE-2012-1954"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1955" ref_id="CVE-2012-1955"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1957" ref_id="CVE-2012-1957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1958" ref_id="CVE-2012-1958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1959" ref_id="CVE-2012-1959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1961" ref_id="CVE-2012-1961"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1962" ref_id="CVE-2012-1962"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1963" ref_id="CVE-2012-1963"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1964" ref_id="CVE-2012-1964"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1967" ref_id="CVE-2012-1967"/>
        <description>[10.0.6-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[10.0.6-1]
- Update to 10.0.6 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:27.254-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:18.042-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:50.625-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:47:55.636-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:47:55.636-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:10.0.6-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27114" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0169 -- vino security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0169.html" ref_id="ELSA-2013-0169"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0904" ref_id="CVE-2011-0904"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0905" ref_id="CVE-2011-0905"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1164" ref_id="CVE-2011-1164"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1165" ref_id="CVE-2011-1165"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4429" ref_id="CVE-2012-4429"/>
        <description>[2.28.1-8]
- Remove spurious 'e' from glib2-devel requirement

[2.28.1-7]
- Bump version number

[2.28.1-6]
- Bump version number

[2.28.1-5]
- Add reachability.patch
  Remove UI about whether the is only reachable locally or not.
  Fix for CVE-2011-1164
  - Bug #553477

[2.28.1-5]
- Add upnp.patch
  Fix for CVE-2011-1165
  - Bug #678846

[2.28.1-5]
- Add clipboard-leak.patch
  Fix for CVE-2012-4429
  - Bug #857250

[2.28.1-5]
- Add vino-2.8.1-sanity-check-fb-update.patch
  Fix for CVE-2011-0904 and CVE-2011-0904
  - Bugs #694456, #694455

[2.28.1-4]
- Translation updates.
  Related: rhbz 575682</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:38.584-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:17.553-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:50.327-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:15:40.133-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:15:40.133-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="vino is earlier than 0:2.28.1-8.el6_3" test_ref="oval:org.mitre.oval:tst:130251"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27113" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0630 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0630.html" ref_id="ELSA-2013-0630"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0228" ref_id="CVE-2013-0228"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0268" ref_id="CVE-2013-0268"/>
        <description>[2.6.32-358.2.1]
- [kernel] utrace: ensure arch_ptrace/ptrace_request can never race with SIGKILL (Oleg Nesterov) [912073 912074] {CVE-2013-0871}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:33.939-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:17.270-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:50.078-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:34:06.443-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:34:06.443-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:130000"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:129736"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:130021"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:129980"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:130004"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:129633"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:129568"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:130041"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:129538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27112" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3038 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3038.html" ref_id="ELSA-2014-3038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3153" ref_id="CVE-2014-3153"/>
        <description>[2.6.39-400.215.2]
- futex: Make lookup_pi_state more robust (Thomas Gleixner)  [Orabug: 18918614]  {CVE-2014-3153}
- futex: Always cleanup owner tid in unlock_pi (Thomas Gleixner)  [Orabug: 18918614]  {CVE-2014-3153}
- futex: Validate atomic acquisition in futex_lock_pi_atomic() (Thomas Gleixner)  [Orabug: 18918614]  {CVE-2014-3153}
- futex: Forbid uaddr1 == uaddr2 in futex_requeue(..., requeue_pi=1) (Thomas Gleixner)  [Orabug: 18918614]  {CVE-2014-3153} {CVE-2014-3153}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:06.500-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:16.958-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:49.922-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127472"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127585"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127546"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127333"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:127379"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.2.el5uek" test_ref="oval:org.mitre.oval:tst:126659"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127179"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127634"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127234"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127552"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127589"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.2.el6uek" test_ref="oval:org.mitre.oval:tst:127651"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27111" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0269 -- axis security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>axis</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0269.html" ref_id="ELSA-2013-0269"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5784" ref_id="CVE-2012-5784"/>
        <description>[0:1.2.1-7.3]
- Add missing connection hostname check against X.509 certificate name
- Resolves: CVE-2012-5784</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:57.414-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:16.711-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:49.750-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T19:01:54.092-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T19:01:54.092-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="axis is earlier than 0:1.2.1-7.3.el6_3" test_ref="oval:org.mitre.oval:tst:130229"/>
          <criterion comment="axis-javadoc is earlier than 0:1.2.1-7.3.el6_3" test_ref="oval:org.mitre.oval:tst:130347"/>
          <criterion comment="axis-manual is earlier than 0:1.2.1-7.3.el6_3" test_ref="oval:org.mitre.oval:tst:130284"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27108" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0597 -- squid security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0597.html" ref_id="ELSA-2014-0597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0128" ref_id="CVE-2014-0128"/>
        <description>[7:3.1.10-20.3]
- Resolves: #1098134 - CVE-2014-0128 squid: denial of service when using
  SSL-Bump

[7:3.1.10-20.2]
- revert: Resolves: #1039088 - issues with timeout on HTTPS connections

[7:3.1.10-20.1]
- Resolves: #1093072 - issues with timeout on HTTPS connections</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:22.495-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:16.260-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:49.581-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35222 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:21.329-05:00">INTERIM</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:46:20.658-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:46:20.658-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="squid is earlier than 7:3.1.10-20.el6_5.3" test_ref="oval:org.mitre.oval:tst:127655"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27102" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2513 -- Unbreakable Enterprise kernel security and bugfix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2513.html" ref_id="ELSA-2013-2513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0871" ref_id="CVE-2013-0871"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1773" ref_id="CVE-2013-1773"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0913" ref_id="CVE-2013-0913"/>
        <description>[2.6.39-400.21.1]
- SPEC: v2.6.39-400.21.1 (Maxim Uvarov)
- xen/mmu: On early bootup, flush the TLB when changing RO->RW bits Xen provided pagetables. (Konrad Rzeszutek Wilk)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:44.022-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:15.169-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:48.963-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129724"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129805"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129781"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129606"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129311"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.21.1.el5uek" test_ref="oval:org.mitre.oval:tst:129770"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:128935"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129789"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129713"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129546"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129296"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.21.1.el6uek" test_ref="oval:org.mitre.oval:tst:129566"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27099" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0596 -- libtasn1 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtasn1</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0596.html" ref_id="ELSA-2014-0596"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3467" ref_id="CVE-2014-3467"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3468" ref_id="CVE-2014-3468"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3469" ref_id="CVE-2014-3469"/>
        <description>[2.3-6]
- added check for null pointer (#1102336)

[2.3-5]
- fix various DER decoding issues (#1102336)

[2.3-4]
- fix CVE-2012-1569 - missing length check when decoding DER lengths (#804920)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:11.700-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:13.893-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:48.506-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:44:48.070-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:44:48.070-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libtasn1 is earlier than 0:2.3-6.el6_5" test_ref="oval:org.mitre.oval:tst:127496"/>
          <criterion comment="libtasn1-devel is earlier than 0:2.3-6.el6_5" test_ref="oval:org.mitre.oval:tst:127536"/>
          <criterion comment="libtasn1-tools is earlier than 0:2.3-6.el6_5" test_ref="oval:org.mitre.oval:tst:127548"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27095" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0199 -- libvirt security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0199.html" ref_id="ELSA-2013-0199"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0170" ref_id="CVE-2013-0170"/>
        <description>[libvirt-0.9.10-21.0.1.el6_3.8]
- Replace docs/et.png in tarball with blank image

[0.9.10-21.el6_3.8]
- rpc: Fix crash on error paths of message dispatching (CVE-2013-0170)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:33.888-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:13.224-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:48.258-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:31:34.561-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:31:34.561-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.9.10-21.0.1.el6_3.8" test_ref="oval:org.mitre.oval:tst:130477"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.0.1.el6_3.8" test_ref="oval:org.mitre.oval:tst:130025"/>
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.0.1.el6_3.8" test_ref="oval:org.mitre.oval:tst:130047"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.0.1.el6_3.8" test_ref="oval:org.mitre.oval:tst:130467"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27093" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3039 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3039.html" ref_id="ELSA-2014-3039"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3153" ref_id="CVE-2014-3153"/>
        <description>kernel-uek
[2.6.32-400.36.2uek]
- futex: Make lookup_pi_state more robust (Thomas Gleixner)  [Orabug: 18918736]  {CVE-2014-3153}
- futex: Always cleanup owner tid in unlock_pi (Thomas Gleixner)  [Orabug: 18918736]  {CVE-2014-3153}
- futex: Validate atomic acquisition in futex_lock_pi_atomic() (Thomas Gleixner)  [Orabug: 18918736]  {CVE-2014-3153}
- futex: Forbid uaddr1 == uaddr2 in futex_requeue(..., requeue_pi=1) (Thomas Gleixner)  [Orabug: 18918736]  {CVE-2014-3153} {CVE-2014-3153}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:32.999-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:12.580-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:47.428-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35271 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:23.249-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:06.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127598"/>
            <criterion comment="mlnx_en-2.6.32-400.36.2.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127656"/>
            <criterion comment="ofa-2.6.32-400.36.2.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127563"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127401"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:126690"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127639"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127578"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127580"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.2.el5uek" test_ref="oval:org.mitre.oval:tst:127454"/>
            <criterion comment="mlnx_en-2.6.32-400.36.2.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127620"/>
            <criterion comment="ofa-2.6.32-400.36.2.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126943"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127597"/>
            <criterion comment="mlnx_en-2.6.32-400.36.2.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127654"/>
            <criterion comment="ofa-2.6.32-400.36.2.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127398"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127470"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127553"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:126984"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127093"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127544"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.2.el6uek" test_ref="oval:org.mitre.oval:tst:127644"/>
            <criterion comment="mlnx_en-2.6.32-400.36.2.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127443"/>
            <criterion comment="ofa-2.6.32-400.36.2.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127226"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27092" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3023 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3023.html" ref_id="ELSA-2014-3023"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6383" ref_id="CVE-2013-6383"/>
        <description>kernel-uek
[2.6.32-400.34.5uek]
- aacraid: missing capable() check in compat ioctl (Dan Carpenter)  [Orabug: 18723276]  {CVE-2013-6383}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:32.493-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:12.238-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:47.247-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127645 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:24.139-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:06.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127326"/>
            <criterion comment="mlnx_en-2.6.32-400.34.5.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127522"/>
            <criterion comment="ofa-2.6.32-400.34.5.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127506"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127178"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127535"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127579"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127456"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127529"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.5.el5uek" test_ref="oval:org.mitre.oval:tst:127618"/>
            <criterion comment="mlnx_en-2.6.32-400.34.5.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:127567"/>
            <criterion comment="ofa-2.6.32-400.34.5.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127335"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127427"/>
            <criterion comment="mlnx_en-2.6.32-400.34.5.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127660"/>
            <criterion comment="ofa-2.6.32-400.34.5.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127262"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127623"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127537"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127686"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127135"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:126785"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.34.5.el6uek" test_ref="oval:org.mitre.oval:tst:127666"/>
            <criterion comment="mlnx_en-2.6.32-400.34.5.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:127645"/>
            <criterion comment="ofa-2.6.32-400.34.5.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:127409"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27085" version="6" class="patch">
      <metadata>
        <title>ELSA-2014-1552 -- openssh security, bug fix, and enhancement update</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1552.html" ref_id="ELSA-2014-1552"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2532" ref_id="CVE-2014-2532"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2653" ref_id="CVE-2014-2653"/>
        <description>[5.3p1-104]
- ignore SIGXFSZ in postauth monitor child (#1133906)

[5.3p1-103]
- don't try to generate DSA keys in the init script in FIPS mode (#1118735)

[5.3p1-102]
- ignore SIGPIPE in ssh-keyscan (#1108836)

[5.3p1-101]
- ssh-add: fix fatal exit when removing card (#1042519)

[5.3p1-100]
- fix race in backported ControlPersist patch (#953088)

[5.3p1-99.2]
- skip requesting smartcard PIN when removing keys from agent (#1042519)

[5.3p1-98]
- add possibility to autocreate only RSA key into initscript (#1111568)
- fix several issues reported by coverity

[5.3p1-97]
- x11 forwarding - be less restrictive when can't bind to one of available addresses
  (#1027197)
- better fork error detection in audit patch (#1028643)
- fix openssh-5.3p1-x11.patch for non-linux platforms (#1100913)

[5.3p1-96]
- prevent a server from skipping SSHFP lookup (#1081338) CVE-2014-2653
- ignore environment variables with embedded '=' or '\0' characters CVE-2014-2532
- backport ControlPersist option (#953088)
- log when a client requests an interactive session and only sftp is allowed (#997377)
- don't try to load RSA1 host key in FIPS mode (#1009959)
- restore Linux oom_adj setting when handling SIGHUP to maintain behaviour over restart
  (#1010429)
- ssh-keygen -V - relative-specified certificate expiry time should be relative to current time
  (#1022459)

[5.3p1-95]
- adjust the key echange DH groups and ssh-keygen according to SP800-131A (#993580)
- log failed integrity test if /etc/system-fips exists (#1020803)
- backport ECDSA and ECDH support (#1028335)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:21.794-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27085 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:42.021-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:35.833-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27085 - Updated States &amp; Objects" date="2015-02-02T15:56:00.526-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-02T16:00:51.935-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:54.076-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssh is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:125098"/>
          <criterion comment="openssh-askpass is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:125378"/>
          <criterion comment="openssh-clients is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:125037"/>
          <criterion comment="openssh-ldap is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:124984"/>
          <criterion comment="openssh-server is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:124560"/>
          <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9.3-104.el6" test_ref="oval:org.mitre.oval:tst:125340"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27084" version="6" class="patch">
      <metadata>
        <title>ELSA-2014-1652 -- openssl security update</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>openssl</product>
          <product>openssl-devel</product>
          <product>openssl-perl</product>
          <product>openssl-static</product>
          <product>openssl-libs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1652.html" ref_id="ELSA-2014-1652"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3513" ref_id="CVE-2014-3513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3567" ref_id="CVE-2014-3567"/>
        <description>[1.0.1e-30.2]
- fix CVE-2014-3567 - memory leak when handling session tickets
- fix CVE-2014-3513 - memory leak in srtp support
- add support for fallback SCSV to partially mitigate CVE-2014-3566
  (padding attack on SSL3)

[1.0.1e-30]
- add ECC TLS extensions to DTLS (#1119800)

[1.0.1e-29]
- fix CVE-2014-3505 - doublefree in DTLS packet processing
- fix CVE-2014-3506 - avoid memory exhaustion in DTLS
- fix CVE-2014-3507 - avoid memory leak in DTLS
- fix CVE-2014-3508 - fix OID handling to avoid information leak
- fix CVE-2014-3509 - fix race condition when parsing server hello
- fix CVE-2014-3510 - fix DoS in anonymous (EC)DH handling in DTLS
- fix CVE-2014-3511 - disallow protocol downgrade via fragmentation

[1.0.1e-28]
- fix CVE-2014-0224 fix that broke EAP-FAST session resumption support

[1.0.1e-26]
- drop EXPORT, RC2, and DES from the default cipher list (#1057520)
- print ephemeral key size negotiated in TLS handshake (#1057715)
- do not include ECC ciphersuites in SSLv2 client hello (#1090952)
- properly detect encryption failure in BIO (#1100819)
- fail on hmac integrity check if the .hmac file is empty (#1105567)
- FIPS mode: make the limitations on DSA, DH, and RSA keygen
  length enforced only if OPENSSL_ENFORCE_MODULUS_BITS environment
  variable is set

[1.0.1e-25]
- fix CVE-2010-5298 - possible use of memory after free
- fix CVE-2014-0195 - buffer overflow via invalid DTLS fragment
- fix CVE-2014-0198 - possible NULL pointer dereference
- fix CVE-2014-0221 - DoS from invalid DTLS handshake packet
- fix CVE-2014-0224 - SSL/TLS MITM vulnerability
- fix CVE-2014-3470 - client-side DoS when using anonymous ECDH

[1.0.1e-24]
- add back support for secp521r1 EC curve

[1.0.1e-23]
- fix CVE-2014-0160 - information disclosure in TLS heartbeat extension

[1.0.1e-22]
- use 2048 bit RSA key in FIPS selftests

[1.0.1e-21]
- add DH_compute_key_padded needed for FIPS CAVS testing
- make 3des strength to be 128 bits instead of 168 (#1056616)
- FIPS mode: do not generate DSA keys and DH parameters &lt; 2048 bits
- FIPS mode: use approved RSA keygen (allows only 2048 and 3072 bit keys)
- FIPS mode: add DH selftest
- FIPS mode: reseed DRBG properly on RAND_add()
- FIPS mode: add RSA encrypt/decrypt selftest
- FIPS mode: add hard limit for 2^32 GCM block encryptions with the same key
- use the key length from configuration file if req -newkey rsa is invoked

[1.0.1e-20]
- fix CVE-2013-4353 - Invalid TLS handshake crash

[1.0.1e-19]
- fix CVE-2013-6450 - possible MiTM attack on DTLS1

[1.0.1e-18]
- fix CVE-2013-6449 - crash when version in SSL structure is incorrect

[1.0.1e-17]
- add back some no-op symbols that were inadvertently dropped</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:20:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:21.060-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27084 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:41.624-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:35.540-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126029 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:24.818-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:53.737-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.1e-30.el6_6.2" test_ref="oval:org.mitre.oval:tst:126012"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.1e-30.el6_6.2" test_ref="oval:org.mitre.oval:tst:126322"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.1e-30.el6_6.2" test_ref="oval:org.mitre.oval:tst:126272"/>
            <criterion comment="openssl-static is earlier than 0:1.0.1e-30.el6_6.2" test_ref="oval:org.mitre.oval:tst:125458"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:125977"/>
            <criterion comment="openssl-devel is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:125518"/>
            <criterion comment="openssl-libs is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:126242"/>
            <criterion comment="openssl-perl is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:126029"/>
            <criterion comment="openssl-static is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:125708"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27083" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0321 -- net-snmp security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>net-snmp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0321.html" ref_id="ELSA-2014-0321"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2284" ref_id="CVE-2014-2284"/>
        <description>[1:5.5-49.0.1.el6_5.1]
- snmptrapd: Fix crash due to access of freed memory (John Haxby) [orabug 14404682]

[1:5.5-49.1]
- added 'diskio' option to snmpd.conf, it's possible to monitor only selected
  devices in diskIOTable (#990674)
- fixed CVE-2014-2284: denial of service flaw in Linux implementation of
  ICMP-MIB (#1073222)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:12.793-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:09.676-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:46.751-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:25:03.815-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:25:03.815-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="net-snmp is earlier than 0:5.5-49.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127780"/>
          <criterion comment="net-snmp-devel is earlier than 0:5.5-49.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127822"/>
          <criterion comment="net-snmp-libs is earlier than 0:5.5-49.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127967"/>
          <criterion comment="net-snmp-perl is earlier than 0:5.5-49.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127845"/>
          <criterion comment="net-snmp-python is earlier than 0:5.5-49.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127997"/>
          <criterion comment="net-snmp-utils is earlier than 0:5.5-49.0.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127771"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27077" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1361 -- xulrunner security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1361.html" ref_id="ELSA-2012-1361"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4193" ref_id="CVE-2012-4193"/>
        <description>[10.0.8-2.0.1.el6_3]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.8-2]
- Added patches from 10.0.9 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:39.164-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:07.094-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:45.893-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:59:45.506-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:59:45.506-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130651"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131083"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130591"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130576"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27075" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1014 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1014.html" ref_id="ELSA-2013-1014"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1500" ref_id="CVE-2013-1500"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1571" ref_id="CVE-2013-1571"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2407" ref_id="CVE-2013-2407"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2412" ref_id="CVE-2013-2412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2443" ref_id="CVE-2013-2443"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2444" ref_id="CVE-2013-2444"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2445" ref_id="CVE-2013-2445"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2446" ref_id="CVE-2013-2446"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2447" ref_id="CVE-2013-2447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2448" ref_id="CVE-2013-2448"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2450" ref_id="CVE-2013-2450"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2452" ref_id="CVE-2013-2452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2453" ref_id="CVE-2013-2453"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2455" ref_id="CVE-2013-2455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2456" ref_id="CVE-2013-2456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2457" ref_id="CVE-2013-2457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2459" ref_id="CVE-2013-2459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2461" ref_id="CVE-2013-2461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2463" ref_id="CVE-2013-2463"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2465" ref_id="CVE-2013-2465"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2469" ref_id="CVE-2013-2469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2470" ref_id="CVE-2013-2470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2471" ref_id="CVE-2013-2471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2472" ref_id="CVE-2013-2472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2473" ref_id="CVE-2013-2473"/>
        <description>[1:1.6.0.0-1.62.1.11.11.90]
- updated to icedtea6-1.11.11.90.tar.gz
- removed upstreamed patch9 jaxp-backport-factoryfinder.patch
- removed upstreamed patch10 fixToFontSecurityFix.patch.
- modified patch3, java-1.6.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#973129</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:33.512-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:03.715-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:45.043-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:40:57.622-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:40:57.622-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129190"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129361"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129329"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129430"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.41.1.11.11.90.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129194"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129322"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129300"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129198"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129439"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:129415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27074" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1009 -- samba4 security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1009.html" ref_id="ELSA-2014-1009"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3560" ref_id="CVE-2014-3560"/>
        <description>[4.0.0-63.rc4]
- resolves: #1126011 - CVE-2014-3560: remote code execution in nmbd.

[4.0.0-62.rc4]
- resolves: #1105501 - CVE-2014-0244: DoS in nmbd.
- resolves: #1108842 - CVE-2014-3493: DoS in smbd with unicode path names.
- resolves: #1105571 - CVE-2014-0178: Uninitialized memory exposure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:21.706-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:03.447-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:44.870-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba4 is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:126706"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:127053"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:126635"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:126982"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:127080"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:126483"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:126807"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:126408"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:126889"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:127101"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:127058"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:127048"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:126188"/>
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:127169"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27073" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0059 -- openssl security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0059.html" ref_id="ELSA-2012-0059"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4577" ref_id="CVE-2011-4577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4108" ref_id="CVE-2011-4108"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4576" ref_id="CVE-2011-4576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4619" ref_id="CVE-2011-4619"/>
        <description>[1.0.0-20.1]
- fix for CVE-2011-4108 &amp; CVE-2012-0050 - DTLS plaintext recovery
  vulnerability and additional DTLS fixes (#771770)
- fix for CVE-2011-4576 - uninitialized SSL 3.0 padding (#771775)
- fix for CVE-2011-4577 - possible DoS through malformed RFC 3779 data (#771778)
- fix for CVE-2011-4619 - SGC restart DoS attack (#771780)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:45:05.795-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:02.839-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:44.632-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:54:19.357-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:54:19.357-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:132827"/>
          <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:132803"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:132819"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:131908"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27071" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2041 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2041.html" ref_id="ELSA-2012-2041"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <description>[2.6.32-300.38.1]

- [net/sfc] limit number of segments per skb on tx (Maxim Uvarov) [Orabug:

  14769994] {CVE-2012-3412}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:54.068-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:02.590-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:44.464-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:130810 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:26.477-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:05.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130626"/>
            <criterion comment="mlnx_en-2.6.32-300.38.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130810"/>
            <criterion comment="ofa-2.6.32-300.38.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130649"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130329"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130923"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130893"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130836"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130817"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.38.1.el5uek" test_ref="oval:org.mitre.oval:tst:130035"/>
            <criterion comment="mlnx_en-2.6.32-300.38.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130906"/>
            <criterion comment="ofa-2.6.32-300.38.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130921"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130783"/>
            <criterion comment="mlnx_en-2.6.32-300.38.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130957"/>
            <criterion comment="ofa-2.6.32-300.38.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130980"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130502"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130068"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130755"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130625"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130844"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.38.1.el6uek" test_ref="oval:org.mitre.oval:tst:130846"/>
            <criterion comment="mlnx_en-2.6.32-300.38.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:131000"/>
            <criterion comment="ofa-2.6.32-300.38.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:131003"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27067" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2040 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2040.html" ref_id="ELSA-2012-2040"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" ref_id="CVE-2012-3412"/>
        <description>[2.6.39-200.34.1]

- [net/sfc] limit number of segments per skb on tx (Maxim Uvarov) [Orabug:

  14769994] {CVE-2012-3412}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:44.052-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:02:00.190-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:44.220-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:130991"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:130847"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:131054"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:130619"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:130972"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.34.1.el5uek" test_ref="oval:org.mitre.oval:tst:131063"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130641"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130897"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130199"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130793"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130808"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-200.34.1.el6uek" test_ref="oval:org.mitre.oval:tst:130860"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27064" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0420 -- qemu-kvm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0420.html" ref_id="ELSA-2014-0420"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0144" ref_id="CVE-2014-0144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0143" ref_id="CVE-2014-0143"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0142" ref_id="CVE-2014-0142"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0145" ref_id="CVE-2014-0145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0150" ref_id="CVE-2014-0150"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0146" ref_id="CVE-2014-0146"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0147" ref_id="CVE-2014-0147"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0148" ref_id="CVE-2014-0148"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

Multiple integer overflow, input validation, logic error, and buffer
overflow flaws were discovered in various QEMU block drivers. An attacker
able to modify a disk image file loaded by a guest could use these flaws to
crash the guest, or corrupt QEMU process memory on the host, potentially
resulting in arbitrary code execution on the host with the privileges of
the QEMU process. (CVE-2014-0143, CVE-2014-0144, CVE-2014-0145,
CVE-2014-0147)

A buffer overflow flaw was found in the way the virtio_net_handle_mac()
function of QEMU processed guest requests to update the table of MAC
addresses. A privileged guest user could use this flaw to corrupt QEMU
process memory on the host, potentially resulting in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2014-0150)

A divide-by-zero flaw was found in the seek_to_sector() function of the
parallels block driver in QEMU. An attacker able to modify a disk image
file loaded by a guest could use this flaw to crash the guest.
(CVE-2014-0142)

A NULL pointer dereference flaw was found in the QCOW2 block driver in
QEMU. An attacker able to modify a disk image file loaded by a guest could
use this flaw to crash the guest. (CVE-2014-0146)

It was found that the block driver for Hyper-V VHDX images did not
correctly calculate BAT (Block Allocation Table) entries due to a missing
bounds check. An attacker able to modify a disk image file loaded by a
guest could use this flaw to crash the guest. (CVE-2014-0148)

The CVE-2014-0143 issues were discovered by Kevin Wolf and Stefan Hajnoczi
of Red Hat, the CVE-2014-0144 issues were discovered by Fam Zheng, Jeff
Cody, Kevin Wolf, and Stefan Hajnoczi of Red Hat, the CVE-2014-0145 issues
were discovered by Stefan Hajnoczi of Red Hat, the CVE-2014-0150 issue was
discovered by Michael S. Tsirkin of Red Hat, the CVE-2014-0142,
CVE-2014-0146, and CVE-2014-0147 issues were discovered by Kevin Wolf of
Red Hat, and the CVE-2014-0148 issue was discovered by Jeff Cody of
Red Hat.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:04.158-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:52.771-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:38.990-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27064 - Removed invalid CVE reference." date="2014-12-05T18:59:00.353-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-12-05T19:07:21.385-05:00">INTERIM</status_change>
            <status_change date="2014-12-22T04:00:07.859-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27064 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:22.685-05:00">INTERIM</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:40:40.795-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:40:40.795-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-guest-agent RPM is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:123951"/>
          <criterion comment="qemu-img RPM is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:124872"/>
          <criterion comment="qemu-kvm RPM is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:124648"/>
          <criterion comment="qemu-kvm-tools RPM is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:124827"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27060" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0920 -- httpd security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0920.html" ref_id="ELSA-2014-0920"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0118" ref_id="CVE-2014-0118"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0226" ref_id="CVE-2014-0226"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0231" ref_id="CVE-2014-0231"/>
        <description>[2.2.15-31.0.1.el6_5]
- replace index.html with Oracle's index page oracle_index.html
- update vstring in specfile

[2.2.15-31]
- mod_cgid: add security fix for CVE-2014-0231
- mod_deflate: add security fix for CVE-2014-0118
- mod_status: add security fix for CVE-2014-0226</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:14.544-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:59.600-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:43.933-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35269 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:43.351-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:30.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.3-87.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127237"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-87.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127077"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-87.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126724"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-87.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:126959"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="httpd is earlier than 0:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127165"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127233"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127288"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:126977"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-31.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127107"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27058" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1307 -- nss security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1307.html" ref_id="ELSA-2014-1307"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1568" ref_id="CVE-2014-1568"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way NSS parsed ASN.1 (Abstract Syntax Notation One)
input from certain RSA signatures. A remote attacker could use this flaw to
forge RSA certificates by providing a specially crafted signature to an
application using NSS. (CVE-2014-1568)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Antoine Delignat-Lavaud and Intel Product Security
Incident Response Team as the original reporters.

All NSS users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, applications using NSS must be restarted for this update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:25.755-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:52.544-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:38.059-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124938"/>
            <criterion comment="nss-devel RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:123989"/>
            <criterion comment="nss-pkcs11-devel RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124894"/>
            <criterion comment="nss-softokn RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124420"/>
            <criterion comment="nss-softokn-devel RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124946"/>
            <criterion comment="nss-softokn-freebl RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124472"/>
            <criterion comment="nss-softokn-freebl-devel RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124947"/>
            <criterion comment="nss-sysinit RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124029"/>
            <criterion comment="nss-tools RPM is earlier than 0:3.16.2-7.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124933"/>
            <criterion comment="nss-util RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124771"/>
            <criterion comment="nss-util-devel RPM is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124963"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss RPM is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:125010"/>
            <criterion comment="nss-devel RPM is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:124167"/>
            <criterion comment="nss-pkcs11-devel RPM is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:124494"/>
            <criterion comment="nss-tools RPM is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:124690"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124964"/>
            <criterion comment="nss-devel RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:125008"/>
            <criterion comment="nss-pkcs11-devel RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:125003"/>
            <criterion comment="nss-softokn RPM is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:124461"/>
            <criterion comment="nss-softokn-devel RPM is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:124965"/>
            <criterion comment="nss-softokn-freebl RPM is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:125025"/>
            <criterion comment="nss-softokn-freebl-devel RPM is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:124638"/>
            <criterion comment="nss-sysinit RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:125018"/>
            <criterion comment="nss-tools RPM is earlier than 0:3.16.1-7.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124086"/>
            <criterion comment="nss-util RPM is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:124471"/>
            <criterion comment="nss-util-devel RPM is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:124323"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27055" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1192 -- spice-server security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>spice-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1192.html" ref_id="ELSA-2013-1192"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4130" ref_id="CVE-2013-4130"/>
        <description>[0.12.0-12.el6_4.3]
- Fixes an abort on unsafe client ring access
  Resolves: rhbz#986298</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:30.144-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:58.550-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:43.695-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:16:50.112-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:16:50.112-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="spice-server is earlier than 0:0.12.0-12.el6_4.3" test_ref="oval:org.mitre.oval:tst:128893"/>
          <criterion comment="spice-server-devel is earlier than 0:0.12.0-12.el6_4.3" test_ref="oval:org.mitre.oval:tst:128578"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27053" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1151 -- openldap security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1151.html" ref_id="ELSA-2012-1151"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2668" ref_id="CVE-2012-2668"/>
        <description>[2.4.23-26.2]
- CVE-2012-2668 (#825875)
    cipher suite selection by name can be ignored
    default cipher suite is always selected

[2.4.23-26.1]
- fix: smbk5pwd module computes invalid LM hashes (#820278)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:10.436-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:58.300-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:43.603-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:26:47.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:26:47.077-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openldap is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:131159"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:131388"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:131392"/>
          <criterion comment="openldap-servers is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:131056"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:130799"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27050" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1166 -- jakarta-commons-httpclient security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1166.html" ref_id="ELSA-2014-1166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3577" ref_id="CVE-2014-3577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6153" ref_id="CVE-2012-6153"/>
        <description>Jakarta Commons HTTPClient implements the client side of HTTP standards.

It was discovered that the HTTPClient incorrectly extracted host name from
an X.509 certificate subject&amp;#39;s Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3577)

For additional information on this flaw, refer to the Knowledgebase
article in the References section.

All jakarta-commons-httpclient users are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:24.738-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:52.348-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:37.137-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:124625 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:25.775-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:52.659-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient RPM is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:124590"/>
            <criterion comment="jakarta-commons-httpclient-demo RPM is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:124928"/>
            <criterion comment="jakarta-commons-httpclient-javadoc RPM is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:124812"/>
            <criterion comment="jakarta-commons-httpclient-manual RPM is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:124349"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient RPM is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:124152"/>
            <criterion comment="jakarta-commons-httpclient-demo RPM is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:124670"/>
            <criterion comment="jakarta-commons-httpclient-javadoc RPM is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:124625"/>
            <criterion comment="jakarta-commons-httpclient-manual RPM is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:124620"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jakarta-commons-httpclient RPM is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:124923"/>
            <criterion comment="jakarta-commons-httpclient-demo RPM is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:124671"/>
            <criterion comment="jakarta-commons-httpclient-javadoc RPM is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:124645"/>
            <criterion comment="jakarta-commons-httpclient-manual RPM is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:124235"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27047" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2512 -- Unbreakable Enterprise kernel Security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2512.html" ref_id="ELSA-2013-2512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0268" ref_id="CVE-2013-0268"/>
        <description><![CDATA[kernel-uek
[2.6.32-300.39.5uek]
- x86/msr: Add capabilities check (Alan Cox) [Orabug: 16481233] {CVE-2013-0268}

ofa-2.6.32-300.39.5.el6uek
mlnx_en-2.6.32-300.39.5.el6uek
* Mon Dec 12 2011 Guru Anbalagane <guru.anbalagane@oracle.com>
- version 1.5.7-0.1

* Tue Nov 01 2011 Joe Jin <joe.jin@oracle.com>
- 1.5.7 for UEK kernel.

* Mon Sep 08 2008 Vladimir Sokolovsky <vlad@mellanox.co.il>
- Added nfsrdma support

* Wed Aug 13 2008 Vladimir Sokolovsky <vlad@mellanox.co.il>
- Added mlx4_en support

* Tue Aug 21 2007 Vladimir Sokolovsky <vlad@mellanox.co.il>
- Added %build
LANG=C
export LANG
unset DISPLAY
 macro

* Sun Jan 28 2007 Vladimir Sokolovsky <vlad@mellanox.co.il>
- Created spec file for kernel-ib]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:02.738-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:55.767-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:43.212-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:128964 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:27.756-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:04.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129927"/>
            <criterion comment="mlnx_en-2.6.32-300.39.5.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128964"/>
            <criterion comment="ofa-2.6.32-300.39.5.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128968"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129657"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129540"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129603"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129585"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129850"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.5.el5uek" test_ref="oval:org.mitre.oval:tst:129001"/>
            <criterion comment="mlnx_en-2.6.32-300.39.5.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129982"/>
            <criterion comment="ofa-2.6.32-300.39.5.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129662"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129447"/>
            <criterion comment="mlnx_en-2.6.32-300.39.5.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129901"/>
            <criterion comment="ofa-2.6.32-300.39.5.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129834"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129854"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129696"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129557"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129961"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129760"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.5.el6uek" test_ref="oval:org.mitre.oval:tst:129951"/>
            <criterion comment="mlnx_en-2.6.32-300.39.5.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:129997"/>
            <criterion comment="ofa-2.6.32-300.39.5.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129059"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27045" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0866 -- samba and samba3x security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0866.html" ref_id="ELSA-2014-0866"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0244" ref_id="CVE-2014-0244"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3493" ref_id="CVE-2014-3493"/>
        <description>[3.6.9-169]

- resolves: #1105499 - CVE-2014-0244: DoS in nmbd.

- resolves: #1108840 - CVE-2014-3493: DoS in smbd with unicode path names.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:32.048-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:55.326-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:42.993-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127425"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127395"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:126535"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127110"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127499"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127492"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127452"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:127231"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127469"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127344"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127433"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127477"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127438"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127404"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127414"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127352"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:126955"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127271"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:127279"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:126901"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27043" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3022 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3022.html" ref_id="ELSA-2014-3022"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0077" ref_id="CVE-2014-0077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6383" ref_id="CVE-2013-6383"/>
        <description>[2.6.39-400.214.6]
- aacraid: missing capable() check in compat ioctl (Dan Carpenter)  [Orabug: 18721962]  {CVE-2013-6383}
- vhost: fix total length when packets are too short (Michael S. Tsirkin)  [Orabug: 18721977]  {CVE-2014-0077}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:29.020-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:54.895-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:42.755-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127466"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127559"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127314"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127663"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127467"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.6.el5uek" test_ref="oval:org.mitre.oval:tst:127688"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127091"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127530"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127417"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127661"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:127612"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.6.el6uek" test_ref="oval:org.mitre.oval:tst:126696"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27042" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3042 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3042.html" ref_id="ELSA-2014-3042"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1737" ref_id="CVE-2014-1737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1738" ref_id="CVE-2014-1738"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6378" ref_id="CVE-2013-6378"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1874" ref_id="CVE-2014-1874"/>
        <description>[2.6.39-400.215.3]
- SELinux: Fix kernel BUG on empty security contexts. (Stephen Smalley)  [Orabug: 19028380]  {CVE-2014-1874}
- floppy: don't write kernel-only members to FDRAWCMD ioctl output (Matthew Daley)  [Orabug: 19028444]  {CVE-2014-1738}
- floppy: ignore kernel-only members in FDRAWCMD ioctl input (Matthew Daley)  [Orabug: 19028438]  {CVE-2014-1737}
- libertas: potential oops in debugfs (Dan Carpenter)  [Orabug: 19028416]  {CVE-2013-6378}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:19.201-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:54.338-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:42.505-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127362"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127276"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127372"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:126585"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127429"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.3.el5uek" test_ref="oval:org.mitre.oval:tst:127575"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127476"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:126619"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127495"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127526"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127413"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.3.el6uek" test_ref="oval:org.mitre.oval:tst:127432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27040" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1505 -- java-1.6.0-openjdk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1505.html" ref_id="ELSA-2013-1505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3829" ref_id="CVE-2013-3829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4002" ref_id="CVE-2013-4002"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5772" ref_id="CVE-2013-5772"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5774" ref_id="CVE-2013-5774"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5778" ref_id="CVE-2013-5778"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5780" ref_id="CVE-2013-5780"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5782" ref_id="CVE-2013-5782"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5783" ref_id="CVE-2013-5783"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5784" ref_id="CVE-2013-5784"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5790" ref_id="CVE-2013-5790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5797" ref_id="CVE-2013-5797"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5802" ref_id="CVE-2013-5802"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5803" ref_id="CVE-2013-5803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5804" ref_id="CVE-2013-5804"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5809" ref_id="CVE-2013-5809"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5814" ref_id="CVE-2013-5814"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5817" ref_id="CVE-2013-5817"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5820" ref_id="CVE-2013-5820"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5823" ref_id="CVE-2013-5823"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5825" ref_id="CVE-2013-5825"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5829" ref_id="CVE-2013-5829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5830" ref_id="CVE-2013-5830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5840" ref_id="CVE-2013-5840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5842" ref_id="CVE-2013-5842"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5849" ref_id="CVE-2013-5849"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5850" ref_id="CVE-2013-5850"/>
        <description>[1:1.6.0.0-1.68.1.11.14]
- updated to icedtea6-1.11.14.tar.gz
- added and applied 1.11.14-fixes.patch, patch10 to fix build issues
- adapted patch8 java-1.6.0-openjdk-timezone-id.patch
- Resolves: rhbz#1017618

[1:1.6.0.1-1.67.1.13.0]
- reverted previous update
- Resolves: rhbz#1017618

[1:1.6.0.1-1.66.1.13.0]
- updated to icedtea 1.13
- updated to openjdk-6-src-b28-04_oct_2013
- added --disable-lcms2 configure switch to fix tck
- removed upstreamed patch7,java-1.6.0-openjdk-jstack.patch
- added patch7 1.13_fixes.patch to fix 1.13 build issues
- adapted patch0 java-1.6.0-openjdk-optflags.patch
- adapted patch3 java-1.6.0-openjdk-java-access-bridge-security.patch
- adapted patch8 java-1.6.0-openjdk-timezone-id.patch
- removed useless runtests parts
- included also java.security.old files
- Resolves: rhbz#1017618</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:10.592-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:51.142-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:41.684-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:11:47.057-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:11:47.057-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128586"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128370"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128122"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:128649"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.42.1.11.14.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127811"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:128800"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:128678"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:127887"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:128270"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 0:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:128515"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27035" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0328 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0328.html" ref_id="ELSA-2014-0328"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1860" ref_id="CVE-2013-1860"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0055" ref_id="CVE-2014-0055"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0069" ref_id="CVE-2014-0069"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0101" ref_id="CVE-2014-0101"/>
        <description>[2.6.32-431.11.2]
- [net] sctp: fix sctp_sf_do_5_1D_ce to verify if peer is AUTH capable (Daniel Borkmann) [1070715 1067451] {CVE-2014-0101}
- [vhost] validate vhost_get_vq_desc return value (Michael S. Tsirkin) [1062579 1058677] {CVE-2014-0055}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:18.958-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:48.697-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:41.031-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:31:57.751-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:31:57.751-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127785"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127954"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127781"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127752"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127616"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127829"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127847"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127885"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127931"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:127884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27032" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1389 -- krb5 security and bug fix update</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
          <product>krb5-devel</product>
          <product>krb5-libs</product>
          <product>krb5-pkinit-openssl</product>
          <product>krb5-server</product>
          <product>krb5-server-ldap</product>
          <product>krb5-workstation</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1389.html" ref_id="ELSA-2014-1389"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1418" ref_id="CVE-2013-1418"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6800" ref_id="CVE-2013-6800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4341" ref_id="CVE-2014-4341"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4344" ref_id="CVE-2014-4344"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4345" ref_id="CVE-2014-4345"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4342" ref_id="CVE-2014-4342"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4343" ref_id="CVE-2014-4343"/>
        <description>[1.10.3-33]
- actually apply that last patch

[1.10.3-32]
- incorporate fix for MITKRB5-SA-2014-001 (CVE-2014-4345, #1128157)

[1.10.3-31]
- ksu: when evaluating .k5users, don't throw away data from .k5users when we're
  not passed a command to run, which implicitly means we're attempting to run
  the target user's shell (#1026721, revised)

[1.10.3-30]
- ksu: when evaluating .k5users, treat lines with just a principal name as if
  they contained the principal name followed by '*', and don't throw away data
  from .k5users when we're not passed a command to run, which implicitly means
  we're attempting to run the target user's shell (#1026721, revised)

[1.10.3-29]
- gssapi: pull in upstream fix for a possible NULL dereference in spnego
  (CVE-2014-4344, #1121510)
- gssapi: pull in proposed-and-accepted fix for a double free in initiators
  (David Woodhouse, CVE-2014-4343, #1121510)

[1.10.3-28]
- correct a type mistake in the backported fix for CVE-2013-1418/CVE-2013-6800

[1.10.3-27]
- pull in backported fix for denial of service by injection of malformed
  GSSAPI tokens (CVE-2014-4341, CVE-2014-4342, #1121510)
- incorporate backported patch for remote crash of KDCs which serve multiple
  realms simultaneously (RT#7756, CVE-2013-1418/CVE-2013-6800, more of

[1.10.3-26]
- pull in backport of patch to not subsequently always require that responses
  come from master KDCs if we get one from a master somewhere along the way
  while chasing referrals (RT#7650, #1113652)

[1.10.3-25]
- ksu: if the -e flag isn't used, use the target user's shell when checking
  for authorization via the target user's .k5users file (#1026721)

[1.10.3-24]
- define _GNU_SOURCE in files where we use EAI_NODATA, to make sure that
  it's declared (#1059730)

[1.10.3-23]
- spnego: pull in patch from master to restore preserving the OID of the
  mechanism the initiator requested when we have multiple OIDs for the same
  mechanism, so that we reply using the same mechanism OID and the initiator
  doesn't get confused (#1087068, RT#7858)

[1.10.3-22]
- add patch from Jatin Nansi to avoid attempting to clear memory at the
  NULL address if krb5_encrypt_helper() returns an error when called
  from encrypt_credencpart() (#1055329, pull #158)

[1.10.3-21]
- drop patch to add additional access() checks to ksu - they shouldn't be
  resulting in any benefit

[1.10.3-20]
- apply patch from Nikolai Kondrashov to pass a default realm set in
  /etc/sysconfig/krb5kdc to the kdb_check_weak helper, so that it doesn't
  produce an error if there isn't one set in krb5.conf (#1009389)

[1.10.3-19]
- packaging: don't Obsoletes: older versions of krb5-pkinit-openssl and
  virtual Provide: krb5-pkinit-openssl on EL6, where we don't need to
  bother with any of that (#1001961)

[1.10.3-18]
- pkinit: backport tweaks to avoid trying to call the prompter callback
  when one isn't set (part of #965721)
- pkinit: backport the ability to use a prompter callback to prompt for
  a password when reading private keys (the rest of #965721)

[1.10.3-17]
- backport fix to not spin on a short read when reading the length of a
  response over TCP (RT#7508, #922884)

[1.10.3-16]
- backport fix for trying all compatible keys when not being strict about
  acceptor names while reading AP-REQs (RT#7883, #1070244)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:16.663-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27032 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:34.355-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:33.253-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="krb5 is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:125523"/>
          <criterion comment="krb5-devel is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:125442"/>
          <criterion comment="krb5-libs is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:125754"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:126441"/>
          <criterion comment="krb5-server is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:126354"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:126429"/>
          <criterion comment="krb5-workstation is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:125470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27031" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1273 -- spice-gtk security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>spice-gtk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1273.html" ref_id="ELSA-2013-1273"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4324" ref_id="CVE-2013-4324"/>
        <description>[0.14-7.3]
- New build with correct patch for CVE-2013-4324

[0.14-7.2]
- Fix race condition in policykit use (CVE-2013-4324)
  Resolves: CVE-2013-4324</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:01.781-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:48.089-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:40.830-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T10:57:40.264-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T10:57:40.264-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="spice-gtk is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:128544"/>
          <criterion comment="spice-glib is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:128590"/>
          <criterion comment="spice-glib-devel is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:128799"/>
          <criterion comment="spice-gtk-devel is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:128733"/>
          <criterion comment="spice-gtk-python is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:128792"/>
          <criterion comment="spice-gtk-tools is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:129019"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27027" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1391 -- glibc security, bug fix, and enhancement update</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
          <product>glibc-common</product>
          <product>glibc-devel</product>
          <product>glibc-headers</product>
          <product>glibc-static</product>
          <product>glibc-utils</product>
          <product>nscd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1391.html" ref_id="ELSA-2014-1391"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4237" ref_id="CVE-2013-4237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4458" ref_id="CVE-2013-4458"/>
        <description>[2.12-1.149]

- Remove gconv transliteration loadable modules support (CVE-2014-5119,

  - _nl_find_locale: Improve handling of crafted locale names (CVE-2014-0475,



[2.12-1.148]

- Switch gettimeofday from INTUSE to libc_hidden_proto (#1099025).



[2.12-1.147]

- Fix stack overflow due to large AF_INET6 requests (CVE-2013-4458, #1111460).

- Fix buffer overflow in readdir_r (CVE-2013-4237, #1111460).



[2.12-1.146]

- Fix memory order when reading libgcc handle (#905941).

- Fix format specifier in malloc_info output (#1027261).

- Fix nscd lookup for innetgr when netgroup has wildcards (#1054846).



[2.12-1.145]

- Add mmap usage to malloc_info output (#1027261).



[2.12-1.144]

- Use NSS_STATUS_TRYAGAIN to indicate insufficient buffer (#1087833).



[2.12-1.143]

- [ppc] Add VDSO IFUNC for gettimeofday (#1028285).

- [ppc] Fix ftime gettimeofday internal call returning bogus data (#1099025).



[2.12-1.142]

- Also relocate in dependency order when doing symbol dependency testing

  (#1019916).



[2.12-1.141]

- Fix infinite loop in nscd when netgroup is empty (#1085273).

- Provide correct buffer length to netgroup queries in nscd (#1074342).

- Return NULL for wildcard values in getnetgrent from nscd (#1085289).

- Avoid overlapping addresses to stpcpy calls in nscd (#1082379).

- Initialize all of datahead structure in nscd (#1074353).



[2.12-1.140]

- Return EAI_AGAIN for AF_UNSPEC when herrno is TRY_AGAIN (#1044628).



[2.12-1.139]

- Do not fail if one of the two responses to AF_UNSPEC fails (#845218).



[2.12-1.138]

- nscd: Make SELinux checks dynamic (#1025933).



[2.12-1.137]

- Fix race in free() of fastbin chunk (#1027101).



[2.12-1.136]

- Fix copy relocations handling of unique objects (#1032628).



[2.12-1.135]

- Fix encoding name for IDN in getaddrinfo (#981942).



[2.12-1.134]

- Fix return code from getent netgroup when the netgroup is not found (#1039988).

- Fix handling of static TLS in dlopen'ed objects (#995972).



[2.12-1.133]

- Don't use alloca in addgetnetgrentX (#1043557).

- Adjust pointers to triplets in netgroup query data (#1043557).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:19.941-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27027 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:32.654-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:32.422-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:126364"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:126184"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:126015"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:126229"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:126359"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:125420"/>
          <criterion comment="nscd is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:126228"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27026" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0696 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0696.html" ref_id="ELSA-2013-0696"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0796" ref_id="CVE-2013-0796"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0800" ref_id="CVE-2013-0800"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0795" ref_id="CVE-2013-0795"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0788" ref_id="CVE-2013-0788"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0793" ref_id="CVE-2013-0793"/>
        <description>firefox
[17.0.5-1.0.1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.5-1]
- Update to 17.0.5 ESR

xulrunner
[17.0.5-1.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.5-1]
- Update to 17.0.5 ESR

[17.0.3-3]
- Added fix for rhbz#916180 - Wrong library directory reference
  in /usr/bin/xulrunner</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:27">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:10:04.455-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:45.208-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:39.883-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:58:39.764-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:58:39.764-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.5-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129861"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129860"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129853"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.5-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129660"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129720"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27024" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1392 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1392.html" ref_id="ELSA-2014-1392"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4483" ref_id="CVE-2013-4483"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4653" ref_id="CVE-2014-4653"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4654" ref_id="CVE-2014-4654"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4655" ref_id="CVE-2014-4655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5077" ref_id="CVE-2014-5077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3601" ref_id="CVE-2014-3601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3122" ref_id="CVE-2014-3122"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2596" ref_id="CVE-2013-2596"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4608" ref_id="CVE-2014-4608"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5045" ref_id="CVE-2014-5045"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0181" ref_id="CVE-2014-0181"/>
        <description>* A NULL pointer dereference flaw was found in the way the Linux kernel's
                      Stream Control Transmission Protocol (SCTP) implementation handled
                      simultaneous connections between the same hosts. A remote attacker could
                      use this flaw to crash the system. (CVE-2014-5077, Important)

                      * An integer overflow flaw was found in the way the Linux kernel's Frame
                      Buffer device implementation mapped kernel memory to user space via the
                      mmap syscall. A local user able to access a frame buffer device file
                      (/dev/fb*) could possibly use this flaw to escalate their privileges on the
                      system. (CVE-2013-2596, Important)

                      * A flaw was found in the way the ipc_rcu_putref() function in the Linux
                      kernel's IPC implementation handled reference counter decrementing.
                      A local, unprivileged user could use this flaw to trigger an Out of Memory
                      (OOM) condition and, potentially, crash the system. (CVE-2013-4483,
                      Moderate)

                      * It was found that the permission checks performed by the Linux kernel
                      when a netlink message was received were not sufficient. A local,
                      unprivileged user could potentially bypass these restrictions by passing a
                      netlink socket as stdout or stderr to a more privileged process and
                      altering the output of this process. (CVE-2014-0181, Moderate)

                      * It was found that the try_to_unmap_cluster() function in the Linux
                      kernel's Memory Managment subsystem did not properly handle page locking in
                      certain cases, which could potentially trigger the BUG_ON() macro in the
                      mlock_vma_page() function. A local, unprivileged user could use this flaw
                      to crash the system. (CVE-2014-3122, Moderate)

                      * A flaw was found in the way the Linux kernel's kvm_iommu_map_pages()
                      function handled IOMMU mapping failures. A privileged user in a guest with
                      an assigned host device could use this flaw to crash the host.
                      (CVE-2014-3601, Moderate)

                      * Multiple use-after-free flaws were found in the way the Linux kernel's
                      Advanced Linux Sound Architecture (ALSA) implementation handled user
                      controls. A local, privileged user could use either of these flaws to crash
                      the system. (CVE-2014-4653, CVE-2014-4654, CVE-2014-4655, Moderate)

                      * A flaw was found in the way the Linux kernel's VFS subsystem handled
                      reference counting when performing unmount operations on symbolic links.
                      A local, unprivileged user could use this flaw to exhaust all available
                      memory on the system or, potentially, trigger a use-after-free error,
                      resulting in a system crash or privilege escalation. (CVE-2014-5045,
                      Moderate)

                      * An integer overflow flaw was found in the way the lzo1x_decompress_safe()
                      function of the Linux kernel's LZO implementation processed Literal Runs.
                      A local attacker could, in extremely rare cases, use this flaw to crash the
                      system or, potentially, escalate their privileges on the system.
                      (CVE-2014-4608, Low)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:43">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:05.285-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:43.914-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:39.231-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126041"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126193"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126817"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126806"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126788"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126829"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126919"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126855"/>
          <criterion comment="perf is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126665"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:126887"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27009" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1778 -- gimp security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1778.html" ref_id="ELSA-2013-1778"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5576" ref_id="CVE-2012-5576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1913" ref_id="CVE-2013-1913"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1978" ref_id="CVE-2013-1978"/>
        <description>[2:2.6.9-6]
- fix overflow in XWD loader (CVE-2013-1913, CVE-2013-1978)

[2:2.6.9-5]
- fix overflow in XWD loader (#879302)

[2:2.6.9-5]
- fix overflow in GIF loader (#847303)

[2:2.6.9-5]
- fix overflows in GIF, CEL loaders (#727800, #839020)

[2:2.6.9-4.1]
- fix various overflows (#666793, #703403, #703405, #703407, #704512)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:31.699-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:41.808-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:37.952-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:03:56.534-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:03:56.534-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gimp is earlier than 0:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:128321"/>
            <criterion comment="gimp-devel is earlier than 0:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:127836"/>
            <criterion comment="gimp-libs is earlier than 0:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:128353"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="gimp is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:128264"/>
            <criterion comment="gimp-devel is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:128414"/>
            <criterion comment="gimp-devel-tools is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:128422"/>
            <criterion comment="gimp-help-browser is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:128135"/>
            <criterion comment="gimp-libs is earlier than 0:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:127490"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27007" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0560 -- libvirt security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0560.html" ref_id="ELSA-2014-0560"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0179" ref_id="CVE-2014-0179"/>
        <description>[0.10.2-29.0.1.el6_5.8]
- Replace docs/et.png in tarball with blank image

[0.10.2-29.el6_5.8]
- LSN-2014-0003: Don't expand entities when parsing XML (CVE-2014-0179)
- QoS: make tc filters match all traffic (rhbz#1096806)
- use virBitmapFree instead of VIR_FREE for cpumask (rhbz#1091206)
- Properly free vcpupin info for unplugged CPUs (rhbz#1091206)
- sanlock: code movement in virLockManagerSanlockAcquire (rhbz#1097227)
- sanlock: don't fail with unregistered domains (rhbz#1097227)
- sanlock: avoid leak in acquire() (rhbz#1097227)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:42.676-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:41.561-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:37.799-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:44:14.370-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:44:14.370-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.10.2-29.0.1.el6_5.8" test_ref="oval:org.mitre.oval:tst:127520"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-29.0.1.el6_5.8" test_ref="oval:org.mitre.oval:tst:127607"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-29.0.1.el6_5.8" test_ref="oval:org.mitre.oval:tst:127423"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-29.0.1.el6_5.8" test_ref="oval:org.mitre.oval:tst:127341"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27006" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1144 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1144.html" ref_id="ELSA-2014-1144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1562" ref_id="CVE-2014-1562"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1567" ref_id="CVE-2014-1567"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1562, CVE-2014-1567)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jan de Mooij as the original reporter of
CVE-2014-1562, and regenrecht as the original reporter of CVE-2014-1567.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.8.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.8.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:17.736-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:51.325-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:28.484-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="firefox RPM is earlier than 0:24.8.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124258"/>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox RPM is earlier than 0:24.8.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124836"/>
            <criterion comment="xulrunner RPM is earlier than 0:24.8.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124875"/>
            <criterion comment="xulrunner-devel RPM is earlier than 0:24.8.0-1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:124822"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox RPM is earlier than 0:24.8.0-2.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124729"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27000" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0581 -- libxml2 security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0581.html" ref_id="ELSA-2013-0581"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0338" ref_id="CVE-2013-0338"/>
        <description>[2.7.6-12.0.1.el6_4.1]
- Update doc/redhat.gif in tarball
- Add libxml2-oracle-enterprise.patch and update logos in tarball</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:49.799-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:40.421-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:37.450-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:38:20.214-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:38:20.214-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.21.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130269"/>
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.21.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130280"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.21.0.1.el5_9.1" test_ref="oval:org.mitre.oval:tst:130286"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.7.6-12.0.1.el6_4.1" test_ref="oval:org.mitre.oval:tst:130256"/>
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-12.0.1.el6_4.1" test_ref="oval:org.mitre.oval:tst:130142"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-12.0.1.el6_4.1" test_ref="oval:org.mitre.oval:tst:130193"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-12.0.1.el6_4.1" test_ref="oval:org.mitre.oval:tst:130250"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26998" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1182 -- 389-ds-base security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1182.html" ref_id="ELSA-2013-1182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4283" ref_id="CVE-2013-4283"/>
        <description>[1.2.11.15.22]
- Resolves: Bug 1000631 - CVE-2013-4283 389-ds-base: ns-slapd crash due to bogus DN -- retry

[1.2.11.15.21]
- Resolves: Bug 1000631 - CVE-2013-4283 389-ds-base: ns-slapd crash due to bogus DN</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:31.734-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:40.170-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:37.336-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:49:11.324-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:49:11.324-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-22.el6_4" test_ref="oval:org.mitre.oval:tst:129098"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-22.el6_4" test_ref="oval:org.mitre.oval:tst:128963"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-22.el6_4" test_ref="oval:org.mitre.oval:tst:129134"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26993" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0522 -- gdb security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gdb</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0522.html" ref_id="ELSA-2013-0522"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4355" ref_id="CVE-2011-4355"/>
        <description>[7.2-60.el6]
- Fix CVE-2011-4355 gdb: arbitrary code execution via .debug_gdb_scripts'
  (Jan Kratochvil, RH BZ 756116).

[7.2-58.el6]
- Fix Backport gdb fix to handle identical binaries via additional build-id
  symlinks' (RH BZ 836966).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:33.208-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:37.741-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:36.651-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:44:48.865-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:44:48.865-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="gdb is earlier than 0:7.2-60.el6" test_ref="oval:org.mitre.oval:tst:130367"/>
          <criterion comment="gdb-gdbserver is earlier than 0:7.2-60.el6" test_ref="oval:org.mitre.oval:tst:130301"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26991" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0831 -- libvirt security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0831.html" ref_id="ELSA-2013-0831"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1962" ref_id="CVE-2013-1962"/>
        <description>[0.10.2-18.0.1.el6_4.5]
- Replace docs/et.png in tarball with blank image

[0.10.2-18.el6_4.5]
- daemon: Fix leak after listing volumes (CVE-2013-1962)
- Don't try to add non-existant devices to ACL (rhbz#958837)
- Avoid spamming logs with cgroups warnings (rhbz#958837)
- audit: Properly encode device path in cgroup audit (rhbz#958839)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:56.001-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:37.490-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:36.483-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:23:11.222-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:23:11.222-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.10.2-18.0.1.el6_4.5" test_ref="oval:org.mitre.oval:tst:129597"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-18.0.1.el6_4.5" test_ref="oval:org.mitre.oval:tst:129419"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-18.0.1.el6_4.5" test_ref="oval:org.mitre.oval:tst:128654"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-18.0.1.el6_4.5" test_ref="oval:org.mitre.oval:tst:129526"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26989" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3019 -- Unbreakable Enterprise kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3019.html" ref_id="ELSA-2014-3019"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2851" ref_id="CVE-2014-2851"/>
        <description>[2.6.39-400.214.5.el6uek]
- net: ipv4: current group_info should be put after using. (Wang, 
Xiaoming)  [Orabug: 18603524]  {CVE-2014-2851}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:32">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:02.934-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:50.279-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:24.517-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124673"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124537"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124835"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124585"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124828"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.39-400.214.5.el6uek" test_ref="oval:org.mitre.oval:tst:124457"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124847"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124779"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124410"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124528"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124548"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.39-400.214.5.el5uek" test_ref="oval:org.mitre.oval:tst:124546"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26988" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0044 -- augeas security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>augeas</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0044.html" ref_id="ELSA-2014-0044"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6412" ref_id="CVE-2013-6412"/>
        <description>[1.0.0-5.1]
- Fix CVE-2013-6412, incorrect permissions under strict umask (RHBZ#1036079)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:25.905-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:37.245-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:36.353-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:00:31.720-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:00:31.720-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="augeas is earlier than 0:1.0.0-5.el6_5.1" test_ref="oval:org.mitre.oval:tst:127614"/>
          <criterion comment="augeas-devel is earlier than 0:1.0.0-5.el6_5.1" test_ref="oval:org.mitre.oval:tst:127657"/>
          <criterion comment="augeas-libs is earlier than 0:1.0.0-5.el6_5.1" test_ref="oval:org.mitre.oval:tst:127632"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26987" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0406 -- java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0406.html" ref_id="ELSA-2014-0406"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0429" ref_id="CVE-2014-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0446" ref_id="CVE-2014-0446"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0451" ref_id="CVE-2014-0451"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0452" ref_id="CVE-2014-0452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0453" ref_id="CVE-2014-0453"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0454" ref_id="CVE-2014-0454"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0455" ref_id="CVE-2014-0455"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0456" ref_id="CVE-2014-0456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0457" ref_id="CVE-2014-0457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0458" ref_id="CVE-2014-0458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0459" ref_id="CVE-2014-0459"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0460" ref_id="CVE-2014-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0461" ref_id="CVE-2014-0461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1876" ref_id="CVE-2014-1876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2397" ref_id="CVE-2014-2397"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2398" ref_id="CVE-2014-2398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2402" ref_id="CVE-2014-2402"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2403" ref_id="CVE-2014-2403"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2412" ref_id="CVE-2014-2412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2413" ref_id="CVE-2014-2413"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2414" ref_id="CVE-2014-2414"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2421" ref_id="CVE-2014-2421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2423" ref_id="CVE-2014-2423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2427" ref_id="CVE-2014-2427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5797" ref_id="CVE-2013-5797"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0455, CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, Security, Sound, and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2014-2412, CVE-2014-0451,
CVE-2014-0458, CVE-2014-2423, CVE-2014-0452, CVE-2014-2414, CVE-2014-2402,
CVE-2014-0446, CVE-2014-2413, CVE-2014-0454, CVE-2014-2427, CVE-2014-0459)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:01.874-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:49.886-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:21.499-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:39:04.797-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:39:04.797-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="java-1.7.0-openjdk RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124426"/>
          <criterion comment="java-1.7.0-openjdk-demo RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124718"/>
          <criterion comment="java-1.7.0-openjdk-devel RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124414"/>
          <criterion comment="java-1.7.0-openjdk-javadoc RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124617"/>
          <criterion comment="java-1.7.0-openjdk-src RPM is earlier than 0:1.7.0.55-2.4.7.1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124369"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26983" version="5" class="patch">
      <metadata>
        <title>ELSA-2012-2044 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2044.html" ref_id="ELSA-2012-2044"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2133" ref_id="CVE-2012-2133"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3400" ref_id="CVE-2012-3400"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3511" ref_id="CVE-2012-3511"/>
        <description>[2.6.32-300.39.1]

- hugepages: fix use after free bug in 'quota' handling [15842385] {CVE-2012-2133}

- mm: Hold a file reference in madvise_remove [15842884] {CVE-2012-3511}

- udf: Fortify loading of sparing table [15843730] {CVE-2012-3400}

- udf: Avoid run away loop when partition table length is corrupt [15843730] {CVE-2012-3400}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:56.033-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:36.337-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:35.833-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:130939 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:25.221-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:03.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130676"/>
            <criterion comment="mlnx_en-2.6.32-300.39.1.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130934"/>
            <criterion comment="ofa-2.6.32-300.39.1.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130816"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130845"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130858"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130670"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130405"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130931"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.1.el5uek" test_ref="oval:org.mitre.oval:tst:130964"/>
            <criterion comment="mlnx_en-2.6.32-300.39.1.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:130633"/>
            <criterion comment="ofa-2.6.32-300.39.1.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130952"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130628"/>
            <criterion comment="mlnx_en-2.6.32-300.39.1.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130939"/>
            <criterion comment="ofa-2.6.32-300.39.1.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130936"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130826"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130962"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130928"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130984"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130948"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-300.39.1.el6uek" test_ref="oval:org.mitre.oval:tst:130521"/>
            <criterion comment="mlnx_en-2.6.32-300.39.1.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:130872"/>
            <criterion comment="ofa-2.6.32-300.39.1.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:130937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26981" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0516 -- evolution security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>evolution</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0516.html" ref_id="ELSA-2013-0516"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3201" ref_id="CVE-2011-3201"/>
        <description>[2.28.3-30.el6]
- Update patch for RH bug #707526 (Prints QP-encoded email encoded)

[2.28.3-29.el6]
- Add patch for RH bug #890642 (Crash due to implicit function declarations)

[2.28.3-28.el6]
- Add patch for RH bug #885558 (CVE 2011-3201).

[2.28.3-27.el6]
- Add patch for RH bug #805239 (calendar alarm notifications).

[2.28.3-26.el6]
- Add patch for RH bug #707526 (contact_list_editor_render_destination)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:41.309-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:36.085-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:35.670-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:31:23.707-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:31:23.707-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="evolution is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:130243"/>
          <criterion comment="evolution-conduits is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:130166"/>
          <criterion comment="evolution-devel is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:130382"/>
          <criterion comment="evolution-help is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:130100"/>
          <criterion comment="evolution-perl is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:130006"/>
          <criterion comment="evolution-pst is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:130353"/>
          <criterion comment="evolution-spamassassin is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:129650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26972" version="4" class="patch">
      <metadata>
        <title>ELSA-2014-1647 -- thunderbird security update</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1647.html" ref_id="ELSA-2014-1647"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1574" ref_id="CVE-2014-1574"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1577" ref_id="CVE-2014-1577"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1578" ref_id="CVE-2014-1578"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1581" ref_id="CVE-2014-1581"/>
        <description>[31.2.0-3.0.1.el6_5]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[31.2.0-3]
- Enabled jemalloc on ppc(64) and s390(x)

[31.2.0-2]
- Update to 31.2.0

[31.1.1-2]
- Sync preferences with Firefox

[31.1.1-1]
- Update to 31.1.1

[31.1.0-1]
- Update to 31.1.0

[31.0-1]
- Rebase to 31 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:20:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:12.101-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26972 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:01:19.875-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:29.440-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird is earlier than 0:31.2.0-3.0.1.el6_6" test_ref="oval:org.mitre.oval:tst:126216"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26968" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-2576 -- unbreakable enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2576.html" ref_id="ELSA-2013-2576"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4299" ref_id="CVE-2013-4299"/>
        <description>[2.6.39-400.209.2]
- dm snapshot: fix data corruption (Mikulas Patocka) [Orabug: 17618492] {CVE-2013-4299}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:13.948-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:32.877-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:35.029-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128138"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128768"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128526"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128929"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:128552"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.209.2.el5uek" test_ref="oval:org.mitre.oval:tst:129070"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:129005"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:128847"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:129074"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:129003"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:128955"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.209.2.el6uek" test_ref="oval:org.mitre.oval:tst:128958"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26963" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1764 -- ruby security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1764.html" ref_id="ELSA-2013-1764"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4164" ref_id="CVE-2013-4164"/>
        <description>[1.8.7.352-13]
- Workaround build issues against OpenSSL with enabled ECC curves.
- Make DRb compatible with OpenSSL 1.0.1.
  * ruby-1.9.3-p222-generate-1024-bits-RSA-key-instead-of-512-bits.patch
- Fix CVE-2013-4164 Heap Overflow in Floating Point Parsing
  * ruby-1.9.3-p484-CVE-2013-4164-ignore-too-long-fraction-part-which-does-not-affect-the-result.patch
  - Resolves: rhbz#1033500</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:45.468-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:32.243-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:34.637-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:46:57.601-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:46:57.601-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:128404"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:128336"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:128232"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:127543"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:128238"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:128466"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:128016"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:128271"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:128413"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26958" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0330 -- samba and samba3x security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0330.html" ref_id="ELSA-2014-0330"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150" ref_id="CVE-2012-6150"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4496" ref_id="CVE-2013-4496"/>
        <description>[3.6.9-168]
- resolves: #1073905 - Fix CVE-2012-6150.
- resolves: #1073905 - Fix CVE-2013-4496.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:16.212-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:30.900-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:33.937-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:15:23.399-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:15:23.399-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127584"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127740"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127574"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127788"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127969"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127298"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127745"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:127948"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="samba is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127734"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127717"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127738"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127605"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127684"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127987"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127773"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127966"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127709"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127842"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127944"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:127901"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26956" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0820 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0820.html" ref_id="ELSA-2013-0820"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0801" ref_id="CVE-2013-0801"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1670" ref_id="CVE-2013-1670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1674" ref_id="CVE-2013-1674"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1675" ref_id="CVE-2013-1675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1676" ref_id="CVE-2013-1676"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1677" ref_id="CVE-2013-1677"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1678" ref_id="CVE-2013-1678"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1679" ref_id="CVE-2013-1679"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1680" ref_id="CVE-2013-1680"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1681" ref_id="CVE-2013-1681"/>
        <description>firefox
[17.0.6-1.0.1.el6_4]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat ones

[17.0.6-1]
- Update to 17.0.6 ESR

[17.0.5-2]
- Updated XulRunner check

xulrunner
[17.0.6-2.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.6-2]
- Update to 17.0.6 ESR

[17.0.5-2]
- Updated nss and nspr versions</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:57.393-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:29.192-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:33.242-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:47:43.491-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:47:43.491-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.6-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129271"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128677"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-1.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:128703"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:17.0.6-1.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129590"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129429"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129455"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26951" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3067 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3067.html" ref_id="ELSA-2014-3067"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0181" ref_id="CVE-2014-0181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4667" ref_id="CVE-2014-4667"/>
        <description>kernel-uek
[3.8.13-35.3.5.el7uek]
- net: Use netlink_ns_capable to verify the permisions of netlink messages (Eric W. Biederman)  [Orabug: 19404231]  {CVE-2014-0181}
- net: Add variants of capable for use on netlink messages (Eric W. Biederman)  [Orabug: 19404231] 
- net: Add variants of capable for use on on sockets (Eric W. Biederman)  [Orabug: 19404231] 
- netlink: Rename netlink_capable netlink_allowed (Eric W. Biederman)  [Orabug: 19404231] 
- sctp: Fix sk_ack_backlog wrap-around problem (Xufeng Zhang)  [Orabug: 19404244]  {CVE-2014-4667}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:24.820-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:27.347-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:32.522-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26951 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:33.454-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:03.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-35.3.5.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:126991"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-35.3.5.el6uek" test_ref="oval:org.mitre.oval:tst:126970"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-35.3.5.el6uek" test_ref="oval:org.mitre.oval:tst:127017"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-35.3.5.el6uek" test_ref="oval:org.mitre.oval:tst:126975"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-35.3.5.el6uek" test_ref="oval:org.mitre.oval:tst:126313"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-35.3.5.el6uek" test_ref="oval:org.mitre.oval:tst:126997"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-35.3.5.el6uek" test_ref="oval:org.mitre.oval:tst:126890"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26944" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1752 -- 389-ds-base security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1752.html" ref_id="ELSA-2013-1752"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4485" ref_id="CVE-2013-4485"/>
        <description>[1.2.11.15-30]

- Resolves: bug 1024977 CVE-2013-4485 389-ds-base: DoS due to improper handling of ger attr searches</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:18.647-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:25.586-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:32.413-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:128607"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:128322"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:128073"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26943" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0514 -- php security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0514.html" ref_id="ELSA-2013-0514"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2688" ref_id="CVE-2012-2688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1398" ref_id="CVE-2011-1398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0831" ref_id="CVE-2012-0831"/>
        <description>It was found that PHP did not check for carriage returns in HTTP headers,
allowing intended HTTP response splitting protections to be bypassed.
Depending on the web browser the victim is using, a remote attacker could
use this flaw to perform HTTP response splitting attacks. (CVE-2011-1398)

An integer signedness issue, leading to a heap-based buffer underflow, was
found in the PHP scandir() function. If a remote attacker could upload an
excessively large number of files to a directory the scandir() function
runs on, it could cause the PHP interpreter to crash or, possibly, execute
arbitrary code. (CVE-2012-2688)

It was found that PHP did not correctly handle the magic_quotes_gpc
configuration directive. This could result in magic_quotes_gpc input
escaping not being applied in all cases, possibly making it easier for a
remote attacker to perform SQL injection attacks. (CVE-2012-0831)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:34.642-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:25.068-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:32.222-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:26:54.879-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:26:54.879-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="php is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129809"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130270"/>
          <criterion comment="php-cli is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130211"/>
          <criterion comment="php-common is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129787"/>
          <criterion comment="php-dba is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130264"/>
          <criterion comment="php-devel is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130148"/>
          <criterion comment="php-embedded is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130241"/>
          <criterion comment="php-enchant is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130104"/>
          <criterion comment="php-fpm is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130238"/>
          <criterion comment="php-gd is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130136"/>
          <criterion comment="php-imap is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130254"/>
          <criterion comment="php-intl is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129318"/>
          <criterion comment="php-ldap is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130190"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129453"/>
          <criterion comment="php-mysql is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130077"/>
          <criterion comment="php-odbc is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130031"/>
          <criterion comment="php-pdo is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129963"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129725"/>
          <criterion comment="php-process is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129543"/>
          <criterion comment="php-pspell is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129967"/>
          <criterion comment="php-recode is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129852"/>
          <criterion comment="php-snmp is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130239"/>
          <criterion comment="php-soap is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130310"/>
          <criterion comment="php-tidy is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130051"/>
          <criterion comment="php-xml is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129833"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:130122"/>
          <criterion comment="php-zts is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:129746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26937" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0743 -- qemu-kvm security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0743.html" ref_id="ELSA-2014-0743"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4148" ref_id="CVE-2013-4148"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4151" ref_id="CVE-2013-4151"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4535" ref_id="CVE-2013-4535"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4536" ref_id="CVE-2013-4536"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4541" ref_id="CVE-2013-4541"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4542" ref_id="CVE-2013-4542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6399" ref_id="CVE-2013-6399"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0182" ref_id="CVE-2014-0182"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2894" ref_id="CVE-2014-2894"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3461" ref_id="CVE-2014-3461"/>
        <description>[0.12.1.2-2.415.el6_5.10]
- kvm-virtio-out-of-bounds-buffer-write-on-invalid-state-l.patch [bz#1095692]
- kvm-usb-sanity-check-setup_index-setup_len-in-post_load.patch [bz#1095743]
- kvm-usb-sanity-check-setup_index-setup_len-in-post_load-2.patch [bz#1095743]
- kvm-virtio-scsi-fix-buffer-overrun-on-invalid-state-load.patch [bz#1095739]
- kvm-virtio-avoid-buffer-overrun-on-incoming-migration.patch [bz#1095735]
- kvm-virtio-validate-num_sg-when-mapping.patch [bz#1095763 bz#1096124]
- kvm-virtio-allow-mapping-up-to-max-queue-size.patch [bz#1095763 bz#1096124]
- kvm-enable-PCI-multiple-segments-for-pass-through-device.patch [bz#1099941]
- kvm-virtio-net-fix-buffer-overflow-on-invalid-state-load.patch [bz#1095675]
- kvm-virtio-validate-config_len-on-load.patch [bz#1095779]
- kvm-usb-fix-up-post-load-checks.patch [bz#1096825]
- kvm-CPU-hotplug-use-apic_id_for_cpu-round-2-RHEL-6-only.patch [bz#1100575]

[0.12.1.2-2.415.el6_5.9]
- kvm-ide-Correct-improper-smart-self-test-counter-reset-i.patch [bz#1087978]
- Resolves: bz#1087978
  (CVE-2014-2894 qemu-kvm: QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART [rhel-6.5.z])</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:27.974-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:23.061-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:31.400-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26937 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:23.373-05:00">INTERIM</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:48:00.074-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:48:00.074-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:127206"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:127611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26936" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0506 -- samba4 security, bug fix and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0506.html" ref_id="ELSA-2013-0506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1182" ref_id="CVE-2012-1182"/>
        <description>[4.0.0-55.rc4]

- Fix dependencies of samba4-test package.

- related: #896142</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:37.569-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:22.691-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:31.234-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:55:45.560-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:55:45.560-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba4 is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:130272"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:129976"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:129812"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:129775"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:129738"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:130143"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:130177"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:129953"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:130121"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:130192"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:130248"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:130094"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:130119"/>
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:130227"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26933" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1764 -- wget security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>wget</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1764.html" ref_id="ELSA-2014-1764"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4877" ref_id="CVE-2014-4877"/>
        <description>[1.14-10.1]
- Fix CVE-2014-4877 wget: FTP symlink arbitrary filesystem access (#1156135)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:30.190-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:22.451-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:31.094-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="wget is earlier than 0:1.12-5.el6_6.1" test_ref="oval:org.mitre.oval:tst:126467"/>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criterion comment="wget is earlier than 0:1.14-10.el7_0.1" test_ref="oval:org.mitre.oval:tst:126684"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26931" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0481 -- kernel security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0481.html" ref_id="ELSA-2012-0481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0879" ref_id="CVE-2012-0879"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1090" ref_id="CVE-2012-1090"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1097" ref_id="CVE-2012-1097"/>
        <description>[2.6.32-220.13.1.el6]
- Revert: [fs] NFSv4: include bitmap in nfsv4 get acl data (Sachin Prabhu) [753231 753232] {CVE-2011-4131}

[2.6.32-220.12.1.el6]
- [net] net_sched: qdisc_alloc_handle() can be too slow (Jiri Pirko) [805458 785891]
- [fs] procfs: add hidepid= and gid= mount options (Jerome Marchand) [770651 770652]
- [fs] procfs: parse mount options (Jerome Marchand) [770651 770652]
- [fs] fuse: add O_DIRECT support (Josef Bacik) [800552 753798]
- [kernel] sysctl: restrict write access to dmesg_restrict (Phillip Lougher) [749248 749251]
- [block] dm io: fix discard support (Mike Snitzer) [799943 758404]
- [net] netlink: wrong size was calculated for vfinfo list blob (Andy Gospodarek) [790338 772136]
- [netdrv] mlx4_en: fix endianness with blue frame support (Steve Best) [789911 750166]
- [usb] Fix deadlock in hid_reset when Dell iDRAC is reset (Shyam Iyer) [797205 782374]
- [virt] vmxnet3: Cap the length of the pskb_may_pull on transmit (bz 790673) (Neil Horman) [801723 790673]
- [scsi] megaraid_sas: Fix instance access in megasas_reset_timer (Tomas Henzl) [790341 759318]
- [netdrv] macvtap: Fix the minor device number allocation (Steve Best) [796828 786518]
- [net] tcp: bind() fix autoselection to share ports (Flavio Leitner) [787764 784671]
- [fs] cifs: change oplock break slow work to very slow work (Jeff Layton) [789373 772874]
- [net] sunrpc: remove xpt_pool (J. Bruce Fields) [795338 753301]
- [net] Potential null skb->dev dereference (Flavio Leitner) [795335 769590]
- [net] pkt_sched: Fix sch_sfq vs tcf_bind_filter oops (Jiri Pirko) [786873 667925]
- [net] mac80211: cancel auth retries when deauthenticating (John Linville) [797241 754356]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:14.974-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:21.625-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:30.753-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T14:38:56.251-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T14:38:56.251-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:131882"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:132472"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:132544"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:131960"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:132583"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:132509"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:131824"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:131996"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:132325"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26926" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0771 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0771.html" ref_id="ELSA-2014-0771"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3153" ref_id="CVE-2014-3153"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1737" ref_id="CVE-2014-1737"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1738" ref_id="CVE-2014-1738"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6378" ref_id="CVE-2013-6378"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0203" ref_id="CVE-2014-0203"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1874" ref_id="CVE-2014-1874"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2039" ref_id="CVE-2014-2039"/>
        <description>[2.6.32-431.20.3]
- [kernel] futex: Make lookup_pi_state more robust (Jerome Marchand) [1104516 1104517] {CVE-2014-3153}
- [kernel] futex: Always cleanup owner tid in unlock_pi (Jerome Marchand) [1104516 1104517] {CVE-2014-3153}
- [kernel] futex: Validate atomic acquisition in futex_lock_pi_atomic() (Jerome Marchand) [1104516 1104517] {CVE-2014-3153}
- [kernel] futex: prevent requeue pi on same futex (Jerome Marchand) [1104516 1104517] {CVE-2014-3153}
- [fs] autofs4: fix device ioctl mount lookup (Ian Kent) [1069630 999708]
- [fs] vfs: introduce kern_path_mountpoint() (Ian Kent) [1069630 999708]
- [fs] vfs: rename user_path_umountat() to user_path_mountpoint_at() (Ian Kent) [1069630 999708]
- [fs] vfs: massage umount_lookup_last() a bit to reduce nesting (Ian Kent) [1069630 999708]
- [fs] vfs: allow umount to handle mountpoints without revalidating them (Ian Kent) [1069630 999708]
- Revert: [fs] vfs: allow umount to handle mountpoints without revalidating them (Ian Kent) [1069630 999708]
- Revert: [fs] vfs: massage umount_lookup_last() a bit to reduce nesting (Ian Kent) [1069630 999708]
- Revert: [fs] vfs: rename user_path_umountat() to user_path_mountpoint_at() (Ian Kent) [1069630 999708]
- Revert: [fs] vfs: introduce kern_path_mountpoint() (Ian Kent) [1069630 999708]
- Revert: [fs] autofs4: fix device ioctl mount lookup (Ian Kent) [1069630 999708]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:16.045-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:19.284-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:30.399-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:127415"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:127450"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:127606"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:127315"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:127564"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:127334"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:127292"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:126881"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:127296"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:127202"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26923" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1293 -- bash security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 5</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1293.html" ref_id="ELSA-2014-1293"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271" ref_id="CVE-2014-6271"/>
        <description>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

A flaw was found in the way Bash evaluated certain specially crafted
environment variables. An attacker could use this flaw to override or
bypass environment restrictions to execute shell commands. Certain
services and applications allow remote unauthenticated attackers to
provide environment variables, allowing them to exploit this issue.
(CVE-2014-6271)

For additional information on the CVE-2014-6271 flaw, refer to the
Knowledgebase article at &lt;A HREF="https://access.redhat.com/articles/1200223">https://access.redhat.com/articles/1200223&lt;/A>

Red Hat would like to thank Stephane Chazelas for reporting this issue.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:22.256-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:47.720-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:10.564-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bash RPM is earlier than 0:4.1.2-15.el6_5.1" test_ref="oval:org.mitre.oval:tst:124796"/>
            <criterion comment="bash-doc RPM is earlier than 0:4.1.2-15.el6_5.1" test_ref="oval:org.mitre.oval:tst:124935"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bash RPM is earlier than 0:4.2.45-5.el7_0.2" test_ref="oval:org.mitre.oval:tst:124345"/>
            <criterion comment="bash-doc RPM is earlier than 0:4.2.45-5.el7_0.2" test_ref="oval:org.mitre.oval:tst:124949"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="bash RPM is earlier than 0:3.2-33.el5.1" test_ref="oval:org.mitre.oval:tst:124844"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26920" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0408 -- java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0408.html" ref_id="ELSA-2014-0408"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0429" ref_id="CVE-2014-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0446" ref_id="CVE-2014-0446"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0451" ref_id="CVE-2014-0451"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0452" ref_id="CVE-2014-0452"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0453" ref_id="CVE-2014-0453"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0456" ref_id="CVE-2014-0456"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0457" ref_id="CVE-2014-0457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0458" ref_id="CVE-2014-0458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0460" ref_id="CVE-2014-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0461" ref_id="CVE-2014-0461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1876" ref_id="CVE-2014-1876"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2397" ref_id="CVE-2014-2397"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2398" ref_id="CVE-2014-2398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2403" ref_id="CVE-2014-2403"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2412" ref_id="CVE-2014-2412"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2414" ref_id="CVE-2014-2414"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2421" ref_id="CVE-2014-2421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2423" ref_id="CVE-2014-2423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2427" ref_id="CVE-2014-2427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5797" ref_id="CVE-2013-5797"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

This update also fixes the following bug:

* The OpenJDK update to IcedTea version 1.13 introduced a regression
related to the handling of the jdk_version_info variable. This variable was
not properly zeroed out before being passed to the Java Virtual Machine,
resulting in a memory leak in the java.lang.ref.Finalizer class.
This update fixes this issue, and memory leaks no longer occur.
(BZ#1085373)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:07.505-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:46.736-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:08.356-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:40:03.441-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:40:03.441-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:124680"/>
            <criterion comment="java-1.6.0-openjdk-demo RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:124417"/>
            <criterion comment="java-1.6.0-openjdk-devel RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:124293"/>
            <criterion comment="java-1.6.0-openjdk-javadoc RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:123890"/>
            <criterion comment="java-1.6.0-openjdk-src RPM is earlier than 0:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:124815"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124871"/>
            <criterion comment="java-1.6.0-openjdk-demo RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124633"/>
            <criterion comment="java-1.6.0-openjdk-devel RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124683"/>
            <criterion comment="java-1.6.0-openjdk-javadoc RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124043"/>
            <criterion comment="java-1.6.0-openjdk-src RPM is earlier than 0:1.6.0.0-5.1.13.3.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:124221"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26919" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3018 -- Unbreakable Enterprise kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3018.html" ref_id="ELSA-2014-3018"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2851" ref_id="CVE-2014-2851"/>
        <description>[3.8.13-26.2.3.el6uek]
- net: ipv4: current group_info should be put after using. (Wang, 
Xiaoming)  [Orabug: 18603523]  {CVE-2014-2851}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:08.410-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:46.606-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:08.075-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:124860 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:35.078-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:02.662-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel-uek-firmware RPM is earlier than 0:3.8.13-26.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:124316"/>
          <criterion comment="kernel-uek-doc RPM is earlier than 0:3.8.13-26.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:124867"/>
          <criterion comment="kernel-uek RPM is earlier than 0:3.8.13-26.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:124870"/>
          <criterion comment="kernel-uek-devel RPM is earlier than 0:3.8.13-26.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:124346"/>
          <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:3.8.13-26.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:124304"/>
          <criterion comment="kernel-uek-debug RPM is earlier than 0:3.8.13-26.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:124784"/>
          <criterion comment="dtrace-modules-3.8.13-26.2.3.el6uek RPM is earlier than 0:0.4.2-3.el6" test_ref="oval:org.mitre.oval:tst:124860"/>
          <criterion comment="kernel-uek-headers RPM is earlier than 0:3.8.13-26.2.3.el6uek" test_ref="oval:org.mitre.oval:tst:124402"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26913" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2047 -- Unbreakable Enterprise kernel security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2047.html" ref_id="ELSA-2012-2047"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2375" ref_id="CVE-2012-2375"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4565" ref_id="CVE-2012-4565"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5517" ref_id="CVE-2012-5517"/>
        <description>[2.6.39-300.17.3]
- mm/hotplug: correctly add new zone to all other nodes zone lists (Jiang Liu)
  [Orabug: 16020976 Bug-db: 14798] {CVE-2012-5517}
- Divide by zero in TCP congestion control Algorithm. (Jesper Dangaard Brouer)
  [Orabug: 16020656 Bug-db: 14798] {CVE-2012-4565}
- Fix length of buffer copied in __nfs4_get_acl_uncached (Sachin Prabhu) [Bug-
  db: 14798] {CVE-2012-2375}
- Avoid reading past buffer when calling GETACL (Sachin Prabhu) [Bug-db: 14798]
  {CVE-2012-2375}
- Avoid beyond bounds copy while caching ACL (Sachin Prabhu) [Bug-db: 14798]
  {CVE-2012-2375}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:34.704-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:15.109-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:30.162-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130778"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130809"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130713"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130716"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130168"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.17.3.el5uek" test_ref="oval:org.mitre.oval:tst:130586"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130707"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:129856"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130631"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130247"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130754"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-300.17.3.el6uek" test_ref="oval:org.mitre.oval:tst:130453"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26909" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-0939 -- xorg-x11-server security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-0939.html" ref_id="ELSA-2012-0939"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4028" ref_id="CVE-2011-4028"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4029" ref_id="CVE-2011-4029"/>
        <description>[1.10.6-1]
- xserver 1.10.6
- Use git-style patch names
- compsize.h, glxcmds.h: Copy from upstream git since they fell out of the
  upstream tarball

[1.10.4-15]
- Undo regression introduced in Patch8007 (#732467)

[1.10.4-14]
- xserver-1.10.4-sync-revert.patch: Revert an edge-case change in IDLETIME
  that appears to be more wrong than right. (#748704)

[1.10.4-13]
- xserver-1.10.4-randr-corner-case.patch: Fix a corner case in initial
  mode selection. (#657580)
- xserver-1.10.4-vbe-no-cache-ddc-support.patch: Only interpret complete
  non-support for DDC extension as 'DDC unavailable'. (#657580)

[1.10.4-11]
- xserver-1.10.4-dix-when-rescaling-from-master-rescale-from-desktop-.patch:
  fix rescaling from master to slave if the pointer (#732467)

[1.10.4-10]
- Add patches to change the screen crossing behaviour for multiple
  ScreenRecs (#732467)
- remove the xorg.conf.man page from our .gitignore - we need to patch it
  now and its part of the upstream distribution

[1.10.4-9]
- xserver-1.10.4-no-24bpp-xaa-composite.patch: Disable Composite at 24bpp
  in XAA (#651934)

[1.10.4-8]
- xserver-1.10.4-fb-picture-crash.patch: Fix crash on invalid pictures (#722680)

[1.10.4-7]
- fix xephyr rendering when using two screens (#757792)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:25:41.447-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:14.034-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:29.978-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:37:12.034-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:37:12.034-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xorg-x11-server is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:131527"/>
          <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:131588"/>
          <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:131514"/>
          <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:130913"/>
          <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:131783"/>
          <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:131565"/>
          <criterion comment="xorg-x11-server-common is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:131609"/>
          <criterion comment="xorg-x11-server-devel is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:131368"/>
          <criterion comment="xorg-x11-server-source is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:131677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26906" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1869 -- pixman security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1869.html" ref_id="ELSA-2013-1869"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6425" ref_id="CVE-2013-6425"/>
        <description>[0.26.2-5.1]
- Fix CVE 2013-6425</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:22.441-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:13.777-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:29.852-05:00">ACCEPTED</status_change>
            <modified comment="duplicate" date="2015-02-11T09:27:14.566-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T09:27:14.566-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pixman is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:128219"/>
            <criterion comment="pixman-devel is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:128278"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pixman is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:127843"/>
            <criterion comment="pixman-devel is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:127636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26897" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1861 -- nss security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
          <product>nss-devel</product>
          <product>nss-pkcs11-devel</product>
          <product>nss-tools</product>
          <product>nss-sysinit</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1861.html" ref_id="ELSA-2013-1861"/>
        <description>[3.15.3-3.0.1.el6_5]
- Added nss-vendor.patch to change vendor

[3.15.3-3]
- Revoke trust in one mis-issued anssi certificate
- Resolves: Bug 1042685 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-6.6]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:49.804-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:10.849-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:29.260-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:13:23.170-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:13:23.170-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:128030"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:128248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:127577"/>
            <criterion comment="nss-tools is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:127863"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128064"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127925"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128115"/>
            <criterion comment="nss-sysinit is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128266"/>
            <criterion comment="nss-tools is earlier than 0:3.15.3-3.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:128176"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26895" version="3" class="patch">
      <metadata>
        <title>ELSA-2012-2013 -- Unbreakable Enterprise kernel security  update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-2013.html" ref_id="ELSA-2012-2013"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4086" ref_id="CVE-2011-4086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1601" ref_id="CVE-2012-1601"/>
        <description>[2.6.39-100.7.1.el6uek]
- KVM: Ensure all vcpus are consistent with in-kernel irqchip settings (Avi
  Kivity) [Bugdb: 13871] {CVE-2012-1601}
- jbd2: clear BH_Delay &amp; BH_Unwritten in journal_unmap_buffer (Eric Sandeen)
  [Bugdb: 13871] {CVE-2011-4086}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:25:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:27:07.428-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:10.358-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:29.007-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132132"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131536"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:132267"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131961"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131589"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.7.1.el5uek" test_ref="oval:org.mitre.oval:tst:131825"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:131811"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132268"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:131991"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132216"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132258"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-100.7.1.el6uek" test_ref="oval:org.mitre.oval:tst:132106"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26894" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0788 -- mod_wsgi security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mod_wsgi</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0788.html" ref_id="ELSA-2014-0788"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0240" ref_id="CVE-2014-0240"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0242" ref_id="CVE-2014-0242"/>
        <description>[3.2-6]
- fix for CVE-2014-0242 (#1104685)

[3.2-4]
- fix for CVE-2014-0240 (#1104687)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:46">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:25.131-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:10.023-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:28.864-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="mod_wsgi is earlier than 0:3.2-6.el6_5" test_ref="oval:org.mitre.oval:tst:127370"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26893" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1767 -- php security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1767.html" ref_id="ELSA-2014-1767"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3668" ref_id="CVE-2014-3668"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3669" ref_id="CVE-2014-3669"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3670" ref_id="CVE-2014-3670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3710" ref_id="CVE-2014-3710"/>
        <description>[5.4.16-23.3]
- fileinfo: fix out-of-bounds read in elf note headers. CVE-2014-3710

[5.4.16-23.2]
- xmlrpc: fix out-of-bounds read flaw in mkgmtime() CVE-2014-3668
- core: fix integer overflow in unserialize() CVE-2014-3669
- exif: fix heap corruption issue in exif_thumbnail() CVE-2014-3670</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:35.067-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:09.243-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:28.260-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126397"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126410"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126530"/>
            <criterion comment="php-common is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126549"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126616"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126194"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126452"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:125941"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126538"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126162"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126374"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126547"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:125685"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126486"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126626"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:125695"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126638"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126542"/>
            <criterion comment="php-process is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126349"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126593"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126566"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126633"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:125790"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126640"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:125822"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126168"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:126552"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126380"/>
            <criterion comment="php-bcmath is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126654"/>
            <criterion comment="php-cli is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126443"/>
            <criterion comment="php-common is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:125988"/>
            <criterion comment="php-dba is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126488"/>
            <criterion comment="php-devel is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126447"/>
            <criterion comment="php-embedded is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126259"/>
            <criterion comment="php-enchant is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126481"/>
            <criterion comment="php-fpm is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126660"/>
            <criterion comment="php-gd is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126604"/>
            <criterion comment="php-intl is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126567"/>
            <criterion comment="php-ldap is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126671"/>
            <criterion comment="php-mbstring is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126281"/>
            <criterion comment="php-mysql is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126490"/>
            <criterion comment="php-mysqlnd is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126384"/>
            <criterion comment="php-odbc is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126328"/>
            <criterion comment="php-pdo is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126657"/>
            <criterion comment="php-pgsql is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126589"/>
            <criterion comment="php-process is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126414"/>
            <criterion comment="php-pspell is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126323"/>
            <criterion comment="php-recode is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126327"/>
            <criterion comment="php-snmp is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126546"/>
            <criterion comment="php-soap is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:125983"/>
            <criterion comment="php-xml is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126621"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:126637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26892" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1148 -- squid security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1148.html" ref_id="ELSA-2014-1148"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4115" ref_id="CVE-2013-4115"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3609" ref_id="CVE-2014-3609"/>
        <description>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A flaw was found in the way Squid handled malformed HTTP Range headers.
A remote attacker able to send HTTP requests to the Squid proxy could use
this flaw to crash Squid. (CVE-2014-3609)

A buffer overflow flaw was found in Squid&amp;#39;s DNS lookup module. A remote
attacker able to send HTTP requests to the Squid proxy could use this flaw
to crash Squid. (CVE-2013-4115)

Red Hat would like to thank the Squid project for reporting the
CVE-2014-3609 issue. Upstream acknowledges Matthew Daley as the original
reporter.

All Squid users are advised to upgrade to this updated package, which
contains backported patches to correct these issues. After installing this
update, the squid service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:27.830-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:45.654-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:04.981-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:124639 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:45.883-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:29.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="squid RPM is earlier than 7:3.1.10-22.el6_5" test_ref="oval:org.mitre.oval:tst:124639"/>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="squid RPM is earlier than 7:2.6.STABLE21-7.el5_10" test_ref="oval:org.mitre.oval:tst:124741"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26887" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1210 -- firefox security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1210.html" ref_id="ELSA-2012-1210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1970" ref_id="CVE-2012-1970"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1972" ref_id="CVE-2012-1972"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1973" ref_id="CVE-2012-1973"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1974" ref_id="CVE-2012-1974"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1975" ref_id="CVE-2012-1975"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1976" ref_id="CVE-2012-1976"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3956" ref_id="CVE-2012-3956"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3957" ref_id="CVE-2012-3957"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3958" ref_id="CVE-2012-3958"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3959" ref_id="CVE-2012-3959"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3960" ref_id="CVE-2012-3960"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3961" ref_id="CVE-2012-3961"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3962" ref_id="CVE-2012-3962"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3963" ref_id="CVE-2012-3963"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3964" ref_id="CVE-2012-3964"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3966" ref_id="CVE-2012-3966"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3967" ref_id="CVE-2012-3967"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3968" ref_id="CVE-2012-3968"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3969" ref_id="CVE-2012-3969"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3970" ref_id="CVE-2012-3970"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3972" ref_id="CVE-2012-3972"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3976" ref_id="CVE-2012-3976"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3978" ref_id="CVE-2012-3978"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3980" ref_id="CVE-2012-3980"/>
        <description>firefox
[10.0.7-1.0.1.el6_3]
- Replace firefox-redhat-default-prefs.js with firefox-oracle-default-prefs.js

[10.0.7-1]
- Update to 10.0.7 ESR

xulrunner
[10.0.7-1.0.1.el6_3]
- Replace xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js

[10.0.7-1]
- Update to 10.0.7 ESR

[10.0.6-2]
- Added fix for rhbz#770276 - Firefox segfaults, should
  have a font dependency</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:22.924-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:06.121-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:26.931-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:03:10.370-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:03:10.370-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.7-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131040"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131282"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131235"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:10.0.7-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130992"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131356"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:131336"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26885" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1850 -- openjpeg security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openjpeg</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1850.html" ref_id="ELSA-2013-1850"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1447" ref_id="CVE-2013-1447"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6045" ref_id="CVE-2013-6045"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6052" ref_id="CVE-2013-6052"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6054" ref_id="CVE-2013-6054"/>
        <description>[1.3-10]
- Apply patch for CVE-2013-6054 CVE-2013-1447 CVE-2013-6045 CVE-2013-6052
Resolves: #1038985 CVE-2013-6054 CVE-2013-1447 CVE-2013-6045 CVE-2013-6052</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:31.984-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:05.553-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:26.672-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:29:22.280-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:29:22.280-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openjpeg is earlier than 0:1.3-10.el6_5" test_ref="oval:org.mitre.oval:tst:128072"/>
          <criterion comment="openjpeg-devel is earlier than 0:1.3-10.el6_5" test_ref="oval:org.mitre.oval:tst:127295"/>
          <criterion comment="openjpeg-libs is earlier than 0:1.3-10.el6_5" test_ref="oval:org.mitre.oval:tst:128093"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26883" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3014 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3014.html" ref_id="ELSA-2014-3014"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0055" ref_id="CVE-2014-0055"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0069" ref_id="CVE-2014-0069"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0101" ref_id="CVE-2014-0101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2523" ref_id="CVE-2014-2523"/>
        <description>kernel-uek
[3.8.13-26.2.2.el6uek]
- netfilter: nf_conntrack_dccp: fix skb_header_pointer API usages (Daniel Borkmann)  [Orabug: 18421673]  {CVE-2014-2523}
- cifs: ensure that uncached writes handle unmapped areas correctly (Jeff Layton)  [Orabug: 18461067]  {CVE-2014-0069} {CVE-2014-0069}
- net: sctp: fix sctp_sf_do_5_1D_ce to verify if we/peer is AUTH capable (Daniel Borkmann)  [Orabug: 18461065]  {CVE-2014-0101}
- vhost-net: insufficient handling of error conditions in get_rx_bufs() (Guangyu Sun)  [Orabug: 18461050]  {CVE-2014-0055}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:38.049-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:04.943-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:26.482-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35289 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:34.749-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:01.598-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-26.2.2.el6uek is earlier than 0:0.4.2-3.el6" test_ref="oval:org.mitre.oval:tst:127835"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-26.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:127792"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-26.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:127154"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-26.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:127720"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-26.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:127513"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-26.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:127805"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-26.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:127912"/>
          <criterion comment="kernel-uek-headers is earlier than 0:3.8.13-26.2.2.el6uek" test_ref="oval:org.mitre.oval:tst:127800"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26880" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-1075 -- qemu-kvm security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1075.html" ref_id="ELSA-2014-1075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0222" ref_id="CVE-2014-0222"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0223" ref_id="CVE-2014-0223"/>
        <description>[0.12.1.2-2.415.el6_5.14]
          - The commit for zrelease .13 was incomplete; the changes to qemu-kvm.spec
            did not include the '%patchNNNN -p1' lines for patches 4647 through 4655;
            so although the patch files themselves were committed, the srpm build
            did not pick them up. In addition, the commit log did not describe the
            patches.
            This commit corrects these problems and bumps the zrelease to .14.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:16.782-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:04.612-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:26.334-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126692 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:21.911-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:50.345-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.14" test_ref="oval:org.mitre.oval:tst:126502"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.14" test_ref="oval:org.mitre.oval:tst:126692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26872" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1193 -- axis security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>axis</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1193.html" ref_id="ELSA-2014-1193"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3596" ref_id="CVE-2014-3596"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5784" ref_id="CVE-2012-5784"/>
        <description>Apache Axis is an implementation of SOAP (Simple Object Access Protocol).
It can be used to build both web service clients and servers.

It was discovered that Axis incorrectly extracted the host name from an
X.509 certificate subject&amp;#39;s Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3596)

For additional information on this flaw, refer to the Knowledgebase article
in the References section.

This issue was discovered by David Jorm and Arun Neelicattu of Red Hat
Product Security.

All axis users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Applications using Apache
Axis must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:19.849-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:44.643-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:01:02.274-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="axis RPM is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:124832"/>
            <criterion comment="axis-javadoc RPM is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:124581"/>
            <criterion comment="axis-manual RPM is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:124399"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="axis RPM is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:124956"/>
            <criterion comment="axis-javadoc RPM is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:124769"/>
            <criterion comment="axis-manual RPM is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:124877"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26871" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1362 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1362.html" ref_id="ELSA-2012-1362"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4193" ref_id="CVE-2012-4193"/>
        <description>[10.0.8-2.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js
- Replace clean.gif in tarball

[10.0.8-2]
- Added patches from 10.0.9 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:18.717-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:03.838-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:26.054-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:10:03.769-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:10:03.769-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:131084"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130898"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26867" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0753 -- icedtea-web security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0753.html" ref_id="ELSA-2013-0753"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1926" ref_id="CVE-2013-1926"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1927" ref_id="CVE-2013-1927"/>
        <description>[1.2.3-2]
- Added (temporally!) posttrans forcing creation of symlinks
  - should be removed next release
- Resolves: rhbz#949094

[1.2.3-1]
- fixed postun - removal of alternatives for plugin restricted to
  (correct) removal process only
- fixed date in changelog previous entry
- Resolves: rhbz#949094

[1.2.3-0]
- Updated to latest ustream release of 1.2 branch - 1.2.3
 - Security Updates
  - CVE-2013-1927, RH884705 - fixed gifar vulnerability
  - CVE-2013-1926, RH916774: Class-loader incorrectly shared for applets with same relative-path.
 - Common
  - PR1161: X509VariableTrustManager does not work correctly with OpenJDK7
 - Plugin
  - PR1157: Applets can hang browser after fatal exception
- Removed upstreamed patch 0- icedtea-web-PR1161.patch
- Resolves: rhbz#949094</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:44.376-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:03.511-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:25.888-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:24:25.588-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:24:25.588-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="icedtea-web is earlier than 0:1.2.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:129366"/>
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.2.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:129712"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26857" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1265 -- libxslt security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxslt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1265.html" ref_id="ELSA-2012-1265"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1202" ref_id="CVE-2011-1202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3970" ref_id="CVE-2011-3970"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2825" ref_id="CVE-2012-2825"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2870" ref_id="CVE-2012-2870"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2871" ref_id="CVE-2012-2871"/>
        <description>[1.1.26-2.0.2.el6_3.1]
- Increment release to avoid ULN conflict with previous release.

[1.1.26-2.0.1.el6_3.1]
- Added libxslt-oracle-enterprise.patch and replaced doc/redhat.gif in tarball

[1.1.26-2.el6_3.1]
- fixes CVE-2011-1202 CVE-2011-3970 CVE-2012-2825 CVE-2012-2871 CVE-2012-2870
- Fix direct pattern matching bug
- Fix popping of vars in xsltCompilerNodePop
- Fix bug 602515
- Fix generate-id() to not expose object addresses (CVE-2011-1202)
- Fix some case of pattern parsing errors (CVE-2011-3970)
- Fix a bug in selecting XSLT elements (CVE-2012-2825)
- Fix portability to upcoming libxml2-2.9.0
- Fix default template processing on namespace nodes (CVE-2012-2871)
- Cleanup of the pattern compilation code (CVE-2012-2870)
- Hardening of code checking node types in various entry point (CVE-2012-2870)
- Hardening of code checking node types in EXSLT (CVE-2012-2870)
- Fix system-property with unknown namespace
- Xsltproc should return an error code if xinclude fails
- Fix a dictionary string usage
- Avoid a heap use after free error</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:23:34.783-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:02.770-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:25.508-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:44:16.893-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:44:16.893-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxslt is earlier than 0:1.1.17-4.0.1.el5_8.3" test_ref="oval:org.mitre.oval:tst:130522"/>
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-4.0.1.el5_8.3" test_ref="oval:org.mitre.oval:tst:131116"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-4.0.1.el5_8.3" test_ref="oval:org.mitre.oval:tst:131087"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxslt is earlier than 0:1.1.26-2.0.2.el6_3.1" test_ref="oval:org.mitre.oval:tst:131174"/>
            <criterion comment="libxslt-devel is earlier than 0:1.1.26-2.0.2.el6_3.1" test_ref="oval:org.mitre.oval:tst:131115"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.26-2.0.2.el6_3.1" test_ref="oval:org.mitre.oval:tst:130266"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26852" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1483 -- thunderbird security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1483.html" ref_id="ELSA-2012-1483"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4201" ref_id="CVE-2012-4201"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4202" ref_id="CVE-2012-4202"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4207" ref_id="CVE-2012-4207"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4209" ref_id="CVE-2012-4209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4214" ref_id="CVE-2012-4214"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4215" ref_id="CVE-2012-4215"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4216" ref_id="CVE-2012-4216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5829" ref_id="CVE-2012-5829"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5830" ref_id="CVE-2012-5830"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5833" ref_id="CVE-2012-5833"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5835" ref_id="CVE-2012-5835"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5839" ref_id="CVE-2012-5839"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5840" ref_id="CVE-2012-5840"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5841" ref_id="CVE-2012-5841"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5842" ref_id="CVE-2012-5842"/>
        <description>[10.0.11-1.0.1.el6_3]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[10.0.11-1]
- Update to 10.0.11 ESR</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:54.478-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:01:01.091-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:24.620-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T17:31:51.728-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T17:31:51.728-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.0.1.el5_8" test_ref="oval:org.mitre.oval:tst:130679"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.0.1.el6_3" test_ref="oval:org.mitre.oval:tst:130162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26840" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1282 -- rtkit security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>rtkit</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1282.html" ref_id="ELSA-2013-1282"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4326" ref_id="CVE-2013-4326"/>
        <description>[0.5-2]
- CVE-2013-4326
  Resolves: #1007174</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:12">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:08.115-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:59.113-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:23.810-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T16:18:25.727-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T16:18:25.727-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="rtkit is earlier than 0:0.5-2.el6_4" test_ref="oval:org.mitre.oval:tst:128927"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26833" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0612 -- ruby security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0612.html" ref_id="ELSA-2013-0612"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4481" ref_id="CVE-2012-4481"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1821" ref_id="CVE-2013-1821"/>
        <description>[1.8.7.352-10]
-  escaping vulnerability about Exception#to_s / NameError#to_s
  * ruby-1.8.7-p371-CVE-2012-4481.patch
  - Related: rhbz#915379

[1.8.7.352-9]
- Fix regression introduced by fix for entity expansion DOS vulnerability
  in REXML (https://bugs.ruby-lang.org/issues/7961)
  * ruby-2.0.0-add-missing-rexml-require.patch
- Related: rhbz#915379

[1.8.7.352-8]
- Addresses entity expansion DoS vulnerability in REXML.
  * ruby-2.0.0-entity-expansion-DoS-vulnerability-in-REXML.patch
- Resolves: rhbz#915379</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:39.409-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:58.747-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:23.623-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:09:24.294-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:09:24.294-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:129769"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:129793"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:130018"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:130085"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:129992"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:129819"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:129871"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:130038"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:129634"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26830" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1635 -- pacemaker security, bug fix, and enhancement update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pacemaker</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1635.html" ref_id="ELSA-2013-1635"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0281" ref_id="CVE-2013-0281"/>
        <description>[1.1.10-14]
- Log: crmd: Supply arguments in the correct order
    Resolves: rhbz#996850
- Fix: Invalid formatting of log message causes crash
    Resolves: rhbz#996850</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:34.288-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:58.476-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:23.402-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="pacemaker is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:128423"/>
          <criterion comment="pacemaker-cli is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:128534"/>
          <criterion comment="pacemaker-cluster-libs is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:128211"/>
          <criterion comment="pacemaker-cts is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:128494"/>
          <criterion comment="pacemaker-doc is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:128512"/>
          <criterion comment="pacemaker-libs is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:128263"/>
          <criterion comment="pacemaker-libs-devel is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:128462"/>
          <criterion comment="pacemaker-remote is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:128471"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26824" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0223 -- kernel security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0223.html" ref_id="ELSA-2013-0223"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4398" ref_id="CVE-2012-4398"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4461" ref_id="CVE-2012-4461"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4530" ref_id="CVE-2012-4530"/>
        <description>[2.6.32-279.22.1]
- [virt] kvm: invalid opcode oops on SET_SREGS with OSXSAVE bit set (Petr Matousek) [862903 862904] {CVE-2012-4461}
- [fs] fuse: optimize __fuse_direct_io() (Brian Foster) [865305 858850]
- [fs] fuse: optimize fuse_get_user_pages() (Brian Foster) [865305 858850]
- [fs] fuse: use get_user_pages_fast() (Brian Foster) [865305 858850]
- [fs] fuse: pass iov[] to fuse_get_user_pages() (Brian Foster) [865305 858850]
- [fs] mm: minor cleanup of iov_iter_single_seg_count() (Brian Foster) [865305 858850]
- [fs] fuse: use req->page_descs[] for argpages cases (Brian Foster) [865305 858850]
to fuse_req (Brian Foster) [865305 858850]
- [fs] fuse: rework fuse_do_ioctl() (Brian Foster) [865305 858850]
- [fs] fuse: rework fuse_perform_write() (Brian Foster) [865305 858850]
- [fs] fuse: rework fuse_readpages() (Brian Foster) [865305 858850]
- [fs] fuse: categorize fuse_get_req() (Brian Foster) [865305 858850]
- [fs] fuse: general infrastructure for pages[] of variable size (Brian Foster) [865305 858850]
- [fs] exec: do not leave bprm->interp on stack (Josh Poimboeuf) [880145 880146] {CVE-2012-4530}
- [fs] exec: use -ELOOP for max recursion depth (Josh Poimboeuf) [880145 880146] {CVE-2012-4530}
- [scsi] have scsi_internal_device_unblock take new state (Frantisek Hrbata) [878774 854140]
- [scsi] add new SDEV_TRANSPORT_OFFLINE state (Chris Leech) [878774 854140]
- [kernel] cpu: fix cpu_chain section mismatch (Frederic Weisbecker) [876090 852148]
- [kernel] sched: Don't modify cpusets during suspend/resume (Frederic Weisbecker) [876090 852148]
- [kernel] sched, cpuset: Drop __cpuexit from cpu hotplug callbacks (Frederic Weisbecker) [876090 852148]
- [kernel] sched: adjust when cpu_active and cpuset configurations are updated during cpu on/offlining (Frantisek Hrbata) [876090 852148]
- [kernel] cpu: return better errno on cpu hotplug failure (Frederic Weisbecker) [876090 852148]
- [kernel] cpu: introduce cpu_notify(), __cpu_notify(), cpu_notify_nofail() (Frederic Weisbecker) [876090 852148]
- [fs] nfs: Properly handle the case where the delegation is revoked (Steve Dickson) [846840 842435]
- [fs] nfs: Move cl_delegations to the nfs_server struct (Steve Dickson) [846840 842435]
- [fs] nfs: Introduce nfs_detach_delegations() (Steve Dickson) [846840 842435]
- [fs] nfs: Fix a number of RCU issues in the NFSv4 delegation code (Steve Dickson) [846840 842435]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:14:58.843-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:57.273-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:23.168-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T13:07:15.452-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T13:07:15.452-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:130023"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:129553"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:130289"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:129895"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:130321"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:130530"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:129570"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:130318"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:130335"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26806" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3072 -- Unbreakable Enterprise kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3072.html" ref_id="ELSA-2014-3072"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917" ref_id="CVE-2014-3917"/>
        <description>kernel-uek
[3.8.13-44.1.1.el7uek]
- auditsc: audit_krule mask accesses need bounds checking (Andy 
Lutomirski)  [Orabug: 19590596]  {CVE-2014-3917}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:51">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:17.242-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:36.966-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:55.931-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:124649 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:25.499-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:01.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:3.8.13-44.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:124454"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:3.8.13-44.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:124637"/>
            <criterion comment="kernel-uek RPM is earlier than 0:3.8.13-44.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:124189"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:3.8.13-44.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:124914"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:3.8.13-44.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:123957"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:3.8.13-44.1.1.el7uek" test_ref="oval:org.mitre.oval:tst:124701"/>
            <criterion comment="dtrace-modules-3.8.13-44.1.1.el7uek RPM is earlier than 0:0.4.3-4.el7" test_ref="oval:org.mitre.oval:tst:124649"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:3.8.13-44.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:124798"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:3.8.13-44.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:124882"/>
            <criterion comment="kernel-uek RPM is earlier than 0:3.8.13-44.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:124706"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:3.8.13-44.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:124906"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:3.8.13-44.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:124318"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:3.8.13-44.1.1.el6uek" test_ref="oval:org.mitre.oval:tst:124810"/>
            <criterion comment="dtrace-modules-3.8.13-44.1.1.el6uek RPM is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:124893"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26786" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0348 -- xalan-j2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xalan-j2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0348.html" ref_id="ELSA-2014-0348"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0107" ref_id="CVE-2014-0107"/>
        <description>Xalan-Java is an XSLT processor for transforming XML documents into HTML,
text, or other XML document types.

It was found that the secure processing feature of Xalan-Java had
insufficient restrictions defined for certain properties and features.
A remote attacker able to provide Extensible Stylesheet Language
Transformations (XSLT) content to be processed by an application using
Xalan-Java could use this flaw to bypass the intended constraints of the
secure processing feature. Depending on the components available in the
classpath, this could lead to arbitrary remote code execution in the
context of the application server running the application that uses
Xalan-Java. (CVE-2014-0107)

All xalan-j2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:00.981-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:35.010-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:53.106-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:17:36.885-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:17:36.885-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xalan-j2 RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124565"/>
            <criterion comment="xalan-j2-demo RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124758"/>
            <criterion comment="xalan-j2-javadoc RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124416"/>
            <criterion comment="xalan-j2-manual RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124813"/>
            <criterion comment="xalan-j2-xsltc RPM is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:124545"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xalan-j2 RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:124159"/>
            <criterion comment="xalan-j2-demo RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:124669"/>
            <criterion comment="xalan-j2-javadoc RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:124696"/>
            <criterion comment="xalan-j2-manual RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:123858"/>
            <criterion comment="xalan-j2-xsltc RPM is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:124519"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26760" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1172 -- procmail security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>procmail</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1172.html" ref_id="ELSA-2014-1172"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3618" ref_id="CVE-2014-3618"/>
        <description>The procmail program is used for local mail delivery. In addition to just
delivering mail, procmail can be used for automatic filtering, presorting,
and other mail handling jobs.

A heap-based buffer overflow flaw was found in procmail&amp;#39;s formail utility.
A remote attacker could send an email with specially crafted headers that,
when processed by formail, could cause procmail to crash or, possibly,
execute arbitrary code as the user running formail. (CVE-2014-3618)

All procmail users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:22.759-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:32.237-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:49.663-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criterion comment="procmail RPM is earlier than 0:3.22-34.el7_0.1" test_ref="oval:org.mitre.oval:tst:124451"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="procmail RPM is earlier than 0:3.22-25.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:124717"/>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="procmail RPM is earlier than 0:3.22-17.1.2.0.1" test_ref="oval:org.mitre.oval:tst:124903"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26748" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0103 -- libvirt security and bug fix update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0103.html" ref_id="ELSA-2014-0103"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6458" ref_id="CVE-2013-6458"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1447" ref_id="CVE-2014-1447"/>
        <description>[0.10.2-29.0.1.el6_5.3]
- Replace docs/et.png in tarball with blank image

[0.10.2-29.el6_5.3]
- qemu: Avoid operations on NULL monitor if VM fails early (rhbz#1055578)
- qemu: Do not access stale data in virDomainBlockStats (CVE-2013-6458)
- qemu: Avoid using stale data in virDomainGetBlockInfo (CVE-2013-6458)
- qemu: Fix job usage in qemuDomainBlockJobImpl (CVE-2013-6458)
- qemu: Fix job usage in qemuDomainBlockCopy (rhbz#1054804)
- qemu: Fix job usage in virDomainGetBlockIoTune (CVE-2013-6458)
- Don't crash if a connection closes early (CVE-2014-1447)
- Really don't crash if a connection closes early (CVE-2014-1447)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:29.869-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:48.724-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:22.425-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:30:29.780-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:30:29.780-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libvirt is earlier than 0:0.10.2-29.0.1.el6_5.3" test_ref="oval:org.mitre.oval:tst:127911"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-29.0.1.el6_5.3" test_ref="oval:org.mitre.oval:tst:128174"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-29.0.1.el6_5.3" test_ref="oval:org.mitre.oval:tst:127937"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-29.0.1.el6_5.3" test_ref="oval:org.mitre.oval:tst:128197"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26747" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0316 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0316.html" ref_id="ELSA-2014-0316"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1493" ref_id="CVE-2014-1493"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1497" ref_id="CVE-2014-1497"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1505" ref_id="CVE-2014-1505"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1508" ref_id="CVE-2014-1508"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1509" ref_id="CVE-2014-1509"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1510" ref_id="CVE-2014-1510"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1511" ref_id="CVE-2014-1511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1512" ref_id="CVE-2014-1512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1513" ref_id="CVE-2014-1513"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1514" ref_id="CVE-2014-1514"/>
        <description>[24.4.0-1.0.1]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[24.4.0-1]
- Update to 24.4.0</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:34.406-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:47.788-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:21.869-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:21:28.814-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:21:28.814-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.0.1.el5_10" test_ref="oval:org.mitre.oval:tst:127287"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:127899"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26742" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0376 -- openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0376.html" ref_id="ELSA-2014-0376"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160" ref_id="CVE-2014-0160"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An information disclosure flaw was found in the way OpenSSL handled TLS and
DTLS Heartbeat Extension packets. A malicious TLS or DTLS client or server
could send a specially crafted TLS or DTLS Heartbeat packet to disclose a
limited portion of memory per request from a connected client or server.
Note that the disclosed portions of memory could potentially include
sensitive information such as private keys. (CVE-2014-0160)

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges Neel Mehta of Google Security as the original
reporter.

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:19:59.896-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:30.094-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:48.208-05:00">ACCEPTED</status_change>
            <modified comment="Deprecated in favor of oval:org.mitre.oval:def:24324" date="2014-12-05T19:22:09.768-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-12-05T19:22:09.768-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="openssl RPM is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:124738"/>
          <criterion comment="openssl-devel RPM is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:124663"/>
          <criterion comment="openssl-perl RPM is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:124780"/>
          <criterion comment="openssl-static RPM is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:124536"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26735" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0292 -- 389-ds-base security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0292.html" ref_id="ELSA-2014-0292"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0132" ref_id="CVE-2014-0132"/>
        <description>[1.2.11.15-32]
- Resolves: bug 1074847 - EMBARGOED CVE-2014-0132 389-ds-base: 389-ds: flaw in parsing authzid can lead to privilege escalation [rhel-6.5.z] (Ticket 47739 - directory server is insecurely misinterpreting authzid on a SASL/GSSAPI bind)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:43.821-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:47.118-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:21.351-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:28:04.119-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:28:04.119-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-32.el6_5" test_ref="oval:org.mitre.oval:tst:127867"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-32.el6_5" test_ref="oval:org.mitre.oval:tst:128013"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-32.el6_5" test_ref="oval:org.mitre.oval:tst:127682"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26731" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1145 -- thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1145.html" ref_id="ELSA-2014-1145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1562" ref_id="CVE-2014-1562"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1567" ref_id="CVE-2014-1567"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1562, CVE-2014-1567)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jan de Mooij as the original reporter of
CVE-2014-1562, and regenrecht as the original reporter of CVE-2014-1567.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.8.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.8.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:21.353-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:28.845-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:47.310-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="thunderbird RPM is earlier than 0:24.8.0-1.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124885"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26716" version="6" class="patch">
      <metadata>
        <title>ELSA-2014-1620 -- java-1.7.0-openjdk security and bug fix update</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1620.html" ref_id="ELSA-2014-1620"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6457" ref_id="CVE-2014-6457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6502" ref_id="CVE-2014-6502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6504" ref_id="CVE-2014-6504"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6506" ref_id="CVE-2014-6506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6511" ref_id="CVE-2014-6511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6512" ref_id="CVE-2014-6512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6517" ref_id="CVE-2014-6517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6519" ref_id="CVE-2014-6519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6531" ref_id="CVE-2014-6531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6558" ref_id="CVE-2014-6558"/>
        <description>[1:1.7.0.65-2.5.3.1.0.1.el7_0]
- Update DISTRO_NAME in specfile

[1:1.7.0.65-2.5.3.1]
- Bump to 2.5.3 for latest security fixes.
- Remove obsolete patches.
- Add hsbootstrap option to pre-build HotSpot when required.
- Resolves: rhbz#1148893</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:20.418-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26716 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:00:45.644-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:21.864-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26716 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:44.654-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:28.046-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.71-2.5.3.1.0.1.el6" test_ref="oval:org.mitre.oval:tst:126152"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.71-2.5.3.1.0.1.el6" test_ref="oval:org.mitre.oval:tst:125910"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.71-2.5.3.1.0.1.el6" test_ref="oval:org.mitre.oval:tst:125795"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.71-2.5.3.1.0.1.el6" test_ref="oval:org.mitre.oval:tst:126334"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.71-2.5.3.1.0.1.el6" test_ref="oval:org.mitre.oval:tst:125415"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.71-2.5.3.1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126344"/>
            <criterion comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.71-2.5.3.1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126394"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.71-2.5.3.1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126412"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.71-2.5.3.1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:125827"/>
            <criterion comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.71-2.5.3.1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126381"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.71-2.5.3.1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:126277"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.71-2.5.3.1.0.1.el7_0" test_ref="oval:org.mitre.oval:tst:125467"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26706" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012-1551 -- mysql security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2012-1551.html" ref_id="ELSA-2012-1551"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5611" ref_id="CVE-2012-5611"/>
        <description>[5.1.66-2]
- Add backported patch for CVE-2012-5611
Resolves: CVE-2012-5611</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:24:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:19:38.998-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:43.511-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:20.067-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:27:07.277-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:27:07.277-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="mysql is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:129867"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:130203"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:130308"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:130556"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:130184"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:130589"/>
          <criterion comment="mysql-server is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:130594"/>
          <criterion comment="mysql-test is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:130532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26687" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0614 -- xulrunner security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0614.html" ref_id="ELSA-2013-0614"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0787" ref_id="CVE-2013-0787"/>
        <description>[17.0.3-2.0.1.el6_4]
- Replaced xulrunner-redhat-default-prefs.js with xulrunner-oracle-default-prefs.js
- Removed XULRUNNER_VERSION from SOURCE21

[17.0.3-2]
- Added fix for #848644</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:09:51.458-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:42.397-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:19.317-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T18:49:06.954-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T18:49:06.954-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129824"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:130015"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129702"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129719"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26681" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-0911 -- kernel security, bug fix, and enhancement update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-0911.html" ref_id="ELSA-2013-0911"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1935" ref_id="CVE-2013-1935"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1943" ref_id="CVE-2013-1943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2017" ref_id="CVE-2013-2017"/>
        <description>[2.6.32-358.11.1]
- [kernel] perf: fix perf_swevent_enabled array out-of-bound access (Petr Matousek) [962793 962794] {CVE-2013-2094}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:38.988-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:41.721-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:19.010-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:21:40.845-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:21:40.845-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:128862"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:129394"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:129357"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:129364"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:129391"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:128642"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:129428"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:128981"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:129502"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26666" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0370 -- httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0370.html" ref_id="ELSA-2014-0370"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6438" ref_id="CVE-2013-6438"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0098" ref_id="CVE-2014-0098"/>
        <description>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

It was found that the mod_dav module did not correctly strip leading white
space from certain elements in a parsed XML. In certain httpd
configurations that use the mod_dav module (for example when using the
mod_dav_svn module), a remote attacker could send a specially crafted DAV
request that would cause the httpd child process to crash or, possibly,
allow the attacker to execute arbitrary code with the privileges of the
&amp;quot;apache&amp;quot; user. (CVE-2013-6438)

A buffer over-read flaw was found in the httpd mod_log_config module.
In configurations where cookie logging is enabled (on Red Hat Enterprise
Linux it is disabled by default), a remote attacker could use this flaw to
crash the httpd child process via an HTTP request with a malformed cookie
header. (CVE-2014-0098)

All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:19:59.401-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:19.557-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:43.251-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:16:07.268-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:16:07.268-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="httpd RPM is earlier than 0:2.2.15-30.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124429"/>
          <criterion comment="httpd-devel RPM is earlier than 0:2.2.15-30.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124425"/>
          <criterion comment="httpd-manual RPM is earlier than 0:2.2.15-30.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124662"/>
          <criterion comment="httpd-tools RPM is earlier than 0:2.2.15-30.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124714"/>
          <criterion comment="mod_ssl RPM is earlier than 0:2.2.15-30.0.1.el6_5" test_ref="oval:org.mitre.oval:tst:124736"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26620" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3086 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3086.html" ref_id="ELSA-2014-3086"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3611" ref_id="CVE-2014-3611"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3185" ref_id="CVE-2014-3185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3181" ref_id="CVE-2014-3181"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3535" ref_id="CVE-2014-3535"/>
        <description>kernel-uek
[2.6.32-400.36.10uek]
- USB: whiteheat: Added bounds checking for bulk command response (James Forshaw)  [Orabug: 19849336]  {CVE-2014-3185}
- HID: fix a couple of off-by-ones (Jiri Kosina)  [Orabug: 19849320]  {CVE-2014-3181}
logging macros to functions (Joe Perches)  [Orabug: 19847630]  {CVE-2014-3535}
logging macros to functions (Joe Perches)  [Orabug: 19847630] 
- vsprintf: Recursive vsnprintf: Add '%pV', struct va_format (Joe Perches)  [Orabug: 19847630] 
- KVM: x86: Improve thread safety in pit (Andy Honig)  [Orabug: 19905688]  {CVE-2014-3611}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:11.488-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:38.132-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:17.658-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:35153 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:29.795-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:57.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126031"/>
            <criterion comment="mlnx_en-2.6.32-400.36.10.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126573"/>
            <criterion comment="ofa-2.6.32-400.36.10.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126434"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126390"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126326"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126528"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126516"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126624"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.10.el5uek" test_ref="oval:org.mitre.oval:tst:126559"/>
            <criterion comment="mlnx_en-2.6.32-400.36.10.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:126243"/>
            <criterion comment="ofa-2.6.32-400.36.10.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126487"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126615"/>
            <criterion comment="mlnx_en-2.6.32-400.36.10.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:126116"/>
            <criterion comment="ofa-2.6.32-400.36.10.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126591"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126133"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126089"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126652"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126266"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126450"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.36.10.el6uek" test_ref="oval:org.mitre.oval:tst:126536"/>
            <criterion comment="mlnx_en-2.6.32-400.36.10.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:125736"/>
            <criterion comment="ofa-2.6.32-400.36.10.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:126503"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26617" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3047 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3047.html" ref_id="ELSA-2014-3047"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943" ref_id="CVE-2014-4943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4699" ref_id="CVE-2014-4699"/>
        <description>[2.6.39-400.215.4]
- l2tp: fix an unprivileged user to kernel privilege escalation (Sasha Levin)  [Orabug: 19229505]  {CVE-2014-4943} {CVE-2014-4943}
- ptrace,x86: force IRET path after a ptrace_stop() (Tejun Heo)  [Orabug: 19230690]  {CVE-2014-4699}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:09.010-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:37.628-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:17.412-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127361"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127508"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127325"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127076"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127410"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.4.el5uek" test_ref="oval:org.mitre.oval:tst:127257"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127459"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127310"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127273"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127524"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127399"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.215.4.el6uek" test_ref="oval:org.mitre.oval:tst:127441"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26607" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0475 -- kernel security and bug fix update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0475.html" ref_id="ELSA-2014-0475"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0077" ref_id="CVE-2014-0077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6383" ref_id="CVE-2013-6383"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2523" ref_id="CVE-2014-2523"/>
        <description>A flaw was found in the way the Linux kernel's netfilter connection
tracking implementation for Datagram Congestion Control Protocol (DCCP)
packets used the skb_header_pointer() function. A remote attacker could use
this flaw to send a specially crafted DCCP packet to crash the system or,
potentially, escalate their privileges on the system.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:13.285-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:36.987-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:17.107-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:51:35.561-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:51:35.561-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:127542"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:127488"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:127515"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:127673"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:126747"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:127241"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:127648"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:127646"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:127713"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:127641"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26597" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-0861 -- lzo security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>lzo</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0861.html" ref_id="ELSA-2014-0861"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4607" ref_id="CVE-2014-4607"/>
        <description>[2.03-3.1.1]
- Fixed integer overflow in decompressor
  Resolves: CVE-2014-4607</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:42">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:07.040-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:34.886-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:16.862-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="lzo is earlier than 0:2.03-3.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127517"/>
            <criterion comment="lzo-devel is earlier than 0:2.03-3.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127267"/>
            <criterion comment="lzo-minilzo is earlier than 0:2.03-3.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:127350"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="lzo is earlier than 0:2.06-6.el7_0.2" test_ref="oval:org.mitre.oval:tst:127299"/>
            <criterion comment="lzo-devel is earlier than 0:2.06-6.el7_0.2" test_ref="oval:org.mitre.oval:tst:127474"/>
            <criterion comment="lzo-minilzo is earlier than 0:2.06-6.el7_0.2" test_ref="oval:org.mitre.oval:tst:127364"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26570" version="6" class="patch">
      <metadata>
        <title>ELSA-2014-1388 -- cups security and bug fix update</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cups</product>
          <product>cups-devel</product>
          <product>cups-libs</product>
          <product>cups-lpd</product>
          <product>cups-php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1388.html" ref_id="ELSA-2014-1388"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2856" ref_id="CVE-2014-2856"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3537" ref_id="CVE-2014-3537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5029" ref_id="CVE-2014-5029"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5030" ref_id="CVE-2014-5030"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5031" ref_id="CVE-2014-5031"/>
        <description>[1:1.4.2-67]
- Revert change to whitelist /rss/ resources, as this was not used
  upstream.

[1:1.4.2-66]
- More STR #4461 fixes from upstream: make rss feeds world-readable,
  but cachedir private.
- Fix icon display in web interface during server restart (STR #4475).

[1:1.4.2-65]
- Fixes for upstream patch for STR #4461: allow /rss/ requests for
  files we created.

[1:1.4.2-64]
- Use upstream patch for STR #4461.

[1:1.4.2-63]
- Applied upstream patch to fix CVE-2014-5029 (bug #1122600),
  CVE-2014-5030 (bug #1128764), CVE-2014-5031 (bug #1128767).
- Fix conf/log file reading for authenticated users (STR #4461).

[1:1.4.2-62]
- Fix CGI handling (STR #4454, bug #1120419).

[1:1.4.2-61]
- fix patch for CVE-2014-3537 (bug #1117794)

[1:1.4.2-60]
- CVE-2014-2856: cross-site scripting flaw (bug #1117798)
- CVE-2014-3537: insufficient checking leads to privilege escalation (bug #1117794)

[1:1.4.2-59]
- Removed package description changes.

[1:1.4.2-58]
- Applied patch to fix 'Bad request' errors as a result of adding in
  httpSetTimeout (STR #4440, also part of svn revision 9967).

[1:1.4.2-57]
- Fixed timeout issue with cupsd reading when there is no data ready
  (bug #1110045).

[1:1.4.2-56]
- Fixed synconclose patch to avoid 'too many arguments for format' warning.
- Fixed settimeout patch to include math.h for fmod declaration.

[1:1.4.2-55]
- Fixed typo preventing web interface from changing driver (bug #1104483,
  STR #3601).
- Fixed SyncOnClose patch (bug #984883).

[1:1.4.2-54]
- Use upstream patch to avoid replaying GSS credentials (bug #1040293).

[1:1.4.2-53]
- Prevent BrowsePoll problems across suspend/resume (bug #769292):
  - Eliminate indefinite wait for response (svn revision 9688).
  - Backported httpSetTimeout API function from CUPS 1.5 and use it in
    the ipp backend so that we wait indefinitely until the printer
    responds, we get a hard error, or the job is cancelled.
  - cups-polld: reconnect on error.
- Added new SyncOnClose directive to use fsync() after altering
  configuration files: defaults to 'Yes'. Adjust in cupsd.conf (bug #984883).
- Fix cupsctl man page typo (bug #1011076).
- Use more portable rpm specfile syntax for conditional php building
  (bug #988598).
- Fix SetEnv directive in cupsd.conf (bug #986495).
- Fix 'collection' attribute sending (bug #978387).
- Prevent format_log segfault (bug #971079).
- Prevent stringpool corruption (bug #884851).
- Don't crash when job queued for printer that times out (bug #855431).
- Upstream patch for broken multipart handling (bug #852846).
- Install /etc/cron.daily/cups with correct permissions (bug #1012482).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:11.256-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26570 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:00:37.889-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:20.480-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:34800 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:23.847-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:48.967-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:126263"/>
          <criterion comment="cups-devel is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:126207"/>
          <criterion comment="cups-libs is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:126329"/>
          <criterion comment="cups-lpd is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:126186"/>
          <criterion comment="cups-php is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:126209"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26566" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3015 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3015.html" ref_id="ELSA-2014-3015"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0055" ref_id="CVE-2014-0055"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0101" ref_id="CVE-2014-0101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2523" ref_id="CVE-2014-2523"/>
        <description>[2.6.39-400.214.4]
- netfilter: nf_conntrack_dccp: fix skb_header_pointer API usages (Daniel Borkmann)  [Orabug: 18462070]  {CVE-2014-2523}
- net: sctp: fix sctp_sf_do_5_1D_ce to verify if we/peer is AUTH capable (Daniel Borkmann)  [Orabug: 18461090]  {CVE-2014-0101}
- vhost-net: insufficient handling of error conditions in get_rx_bufs() (Guangyu Sun)  [Orabug: 18461089]  {CVE-2014-0055}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:41.097-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:33.690-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:16.123-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127731"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127698"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:126999"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127694"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127664"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.4.el5uek" test_ref="oval:org.mitre.oval:tst:127591"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127629"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127722"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127790"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127949"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127670"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.39-400.214.4.el6uek" test_ref="oval:org.mitre.oval:tst:127837"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26555" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3075 -- bash security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3075.html" ref_id="ELSA-2014-3075"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7169" ref_id="CVE-2014-7169"/>
        <description>[4.1.2-15.1.0.1]
- Preliminary fix for CVE-2014-7169</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:23.178-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:02.261-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:37.583-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="bash RPM is earlier than 0:4.1.2-15.el6_5.1.0.1" test_ref="oval:org.mitre.oval:tst:124688"/>
          <criterion comment="bash-doc RPM is earlier than 0:4.1.2-15.el6_5.1.0.1" test_ref="oval:org.mitre.oval:tst:124891"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26541" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1142 -- thunderbird security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1142.html" ref_id="ELSA-2013-1142"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1701" ref_id="CVE-2013-1701"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1709" ref_id="CVE-2013-1709"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1710" ref_id="CVE-2013-1710"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1713" ref_id="CVE-2013-1713"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1714" ref_id="CVE-2013-1714"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1717" ref_id="CVE-2013-1717"/>
        <description>[17.0.8-5.0.1.el6_4]
- Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[17.0.8-5]
- Update to 17.0.8 ESR
- Added strict aliasing patch (mozbz#821502)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:37.480-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:30.077-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:14.905-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:23:32.323-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:23:32.323-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.0.1.el5_9" test_ref="oval:org.mitre.oval:tst:129217"/>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.0.1.el6_4" test_ref="oval:org.mitre.oval:tst:129234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26538" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-3074 -- Unbreakable Enterprise kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3074.html" ref_id="ELSA-2014-3074"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917" ref_id="CVE-2014-3917"/>
        <description>[2.6.39-400.215.10.el6uek]
- auditsc: audit_krule mask accesses need bounds checking (Andy 
Lutomirski)  [Orabug: 19590597]  {CVE-2014-3917}

[2.6.39-400.215.9.el6uek]
- oracleasm: Add support for new error return codes from block/SCSI 
(Martin K. Petersen)  [Orabug: 18438934]

[2.6.39-400.215.8.el6uek]
- ib_ipoib: CSUM support in connected mode (Yuval Shaia)  [Orabug: 
18692878] - net: Reduce high cpu usage in bonding driver by do_csum 
(Venkat Venkatsubra)  [Orabug: 18141731] - [random] Partially revert 
6d7c7e49: random: make 'add_interrupt_randomness() (John Sobecki) 
[Orabug: 17740293] - oracleasm: claim FMODE_EXCL access on disk during 
asm_open (Srinivas Eeda)  [Orabug: 19453460] - notify block layer when 
using temporary change to cache_type (Vaughan Cao)  [Orabug: 19448451] - 
sd: Fix parsing of 'temporary ' cache mode prefix (Ben Hutchings) 
[Orabug: 19448451] - sd: fix array cache flushing bug causing 
performance problems (James Bottomley)  [Orabug: 19448451] - block: fix 
max discard sectors limit (James Bottomley)  [Orabug: 18961244] - 
xen-netback: fix deadlock in high memory pressure (Junxiao Bi)  [Orabug: 
18959416] - sdp: fix keepalive functionality (shamir rabinovitch) 
[Orabug: 18728784] - SELinux: Fix possible NULL pointer dereference in 
selinux_inode_permission() (Steven Rostedt)  [Orabug: 18552029] - 
refcount: take rw_lock in ocfs2_reflink (Wengang Wang)  [Orabug: 
18406219] - ipv6: check return value for dst_alloc (Madalin Bucur) 
[Orabug: 17865160] - cciss: bug fix to prevent cciss from loading in 
kdump crash kernel (Mike Miller)  [Orabug: 17740446] - configfs: fix 
race between dentry put and lookup (Junxiao Bi)  [Orabug: 17627075]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:20.394-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:01:00.442-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:36.475-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124797"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124854"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124802"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124809"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124476"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.39-400.215.10.el6uek" test_ref="oval:org.mitre.oval:tst:124686"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124563"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124944"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124912"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124826"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124927"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.39-400.215.10.el5uek" test_ref="oval:org.mitre.oval:tst:124831"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26531" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-0790 -- dovecot security update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0790.html" ref_id="ELSA-2014-0790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3430" ref_id="CVE-2014-3430"/>
        <description>[1:2.0.9-7.1]
- fix CVE-2014-3430: denial of service through maxxing out SSL connections (#1108001)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:36.340-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:29.812-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:14.628-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127471 - Modified Linux Oracle patches to correct Epochs." date="2015-02-04T10:36:00.433-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-04T10:38:21.440-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:48.560-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dovecot is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:127063"/>
            <criterion comment="dovecot-devel is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:127440"/>
            <criterion comment="dovecot-mysql is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:127505"/>
            <criterion comment="dovecot-pgsql is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:127294"/>
            <criterion comment="dovecot-pigeonhole is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:127396"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dovecot is earlier than 1:2.2.10-4.el7_0.1" test_ref="oval:org.mitre.oval:tst:127268"/>
            <criterion comment="dovecot-mysql is earlier than 1:2.2.10-4.el7_0.1" test_ref="oval:org.mitre.oval:tst:127471"/>
            <criterion comment="dovecot-pgsql is earlier than 1:2.2.10-4.el7_0.1" test_ref="oval:org.mitre.oval:tst:127500"/>
            <criterion comment="dovecot-pigeonhole is earlier than 1:2.2.10-4.el7_0.1" test_ref="oval:org.mitre.oval:tst:127145"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26523" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1167 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1167.html" ref_id="ELSA-2014-1167"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0205" ref_id="CVE-2014-0205"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3535" ref_id="CVE-2014-3535"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917" ref_id="CVE-2014-3917"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943" ref_id="CVE-2014-4943"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4699" ref_id="CVE-2014-4699"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4667" ref_id="CVE-2014-4667"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel&amp;#39;s futex subsystem handled
reference counting when requeuing futexes during futex_wait(). A local,
unprivileged user could use this flaw to zero out the reference counter of
an inode or an mm struct that backs up the memory area of the futex, which
could lead to a use-after-free flaw, resulting in a system crash or,
potentially, privilege escalation. (CVE-2014-0205, Important)

* A NULL pointer dereference flaw was found in the way the Linux kernel&amp;#39;s
networking implementation handled logging while processing certain invalid
packets coming in via a VxLAN interface. A remote attacker could use this
flaw to crash the system by sending a specially crafted packet to such an
interface. (CVE-2014-3535, Important)

* An out-of-bounds memory access flaw was found in the Linux kernel&amp;#39;s
system call auditing implementation. On a system with existing audit rules
defined, a local, unprivileged user could use this flaw to leak kernel
memory to user space or, potentially, crash the system. (CVE-2014-3917,
Moderate)

* An integer underflow flaw was found in the way the Linux kernel&amp;#39;s Stream
Control Transmission Protocol (SCTP) implementation processed certain
COOKIE_ECHO packets. By sending a specially crafted SCTP packet, a remote
attacker could use this flaw to prevent legitimate connections to a
particular SCTP server socket to be made. (CVE-2014-4667, Moderate)

Red Hat would like to thank Gopal Reddy Kodudula of Nokia Siemens Networks
for reporting CVE-2014-4667. The security impact of the CVE-2014-0205 issue
was discovered by Mateusz Guzik of Red Hat.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:20:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:16.263-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:00:57.193-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:34.990-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124799"/>
          <criterion comment="kernel-abi-whitelists RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124709"/>
          <criterion comment="kernel-debug RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124112"/>
          <criterion comment="kernel-debug-devel RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124789"/>
          <criterion comment="kernel-devel RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124884"/>
          <criterion comment="kernel-doc RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124898"/>
          <criterion comment="kernel-firmware RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124689"/>
          <criterion comment="kernel-headers RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124866"/>
          <criterion comment="perf RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124739"/>
          <criterion comment="python-perf RPM is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:124782"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26522" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3002 -- Unbreakable Enterprise kernel security and bug fix update  (Unbreakable Enterprise Kernel Release 3 QU1) (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>dtrace-modules-headers</product>
          <product>dtrace-modules-provider-headers</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3002.html" ref_id="ELSA-2014-3002"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2147" ref_id="CVE-2013-2147"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2148" ref_id="CVE-2013-2148"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2850" ref_id="CVE-2013-2850"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2893" ref_id="CVE-2013-2893"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2895" ref_id="CVE-2013-2895"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2896" ref_id="CVE-2013-2896"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2897" ref_id="CVE-2013-2897"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2898" ref_id="CVE-2013-2898"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2899" ref_id="CVE-2013-2899"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4350" ref_id="CVE-2013-4350"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4205" ref_id="CVE-2013-4205"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4247" ref_id="CVE-2013-4247"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4270" ref_id="CVE-2013-4270"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4300" ref_id="CVE-2013-4300"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6431" ref_id="CVE-2013-6431"/>
        <description>[3.8.13-26.el6uek]

- spec: Don't remove crashkernel=auto setting (Jerry Snitselaar) [Orabug: 18137993]
dtrace-modules-3.8.13-26.el6uek

[0.4.2-3]

- Obsolete the old provider headers package. [Orabug: 18061595]</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:16.988-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:28.289-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:13.944-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127803 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:28.122-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:56.160-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-26.el6uek is earlier than 0:0.4.2-3.el6" test_ref="oval:org.mitre.oval:tst:127803"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-26.el6uek" test_ref="oval:org.mitre.oval:tst:128061"/>
          <criterion comment="dtrace-modules-headers is earlier than 0:0.4.2-3.el6" test_ref="oval:org.mitre.oval:tst:127902"/>
          <criterion comment="dtrace-modules-provider-headers is earlier than 0:0.4.2-3.el6" test_ref="oval:org.mitre.oval:tst:127789"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-26.el6uek" test_ref="oval:org.mitre.oval:tst:128154"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-26.el6uek" test_ref="oval:org.mitre.oval:tst:128131"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-26.el6uek" test_ref="oval:org.mitre.oval:tst:127889"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-26.el6uek" test_ref="oval:org.mitre.oval:tst:127749"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-26.el6uek" test_ref="oval:org.mitre.oval:tst:127768"/>
          <criterion comment="kernel-uek-headers is earlier than 0:3.8.13-26.el6uek" test_ref="oval:org.mitre.oval:tst:128052"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26519" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3081 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3081.html" ref_id="ELSA-2014-3081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4653" ref_id="CVE-2014-4653"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4654" ref_id="CVE-2014-4654"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4655" ref_id="CVE-2014-4655"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5077" ref_id="CVE-2014-5077"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3601" ref_id="CVE-2014-3601"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3535" ref_id="CVE-2014-3535"/>
        <description>kernel-uek
        [3.8.13-44.1.3.el7uek]
        - ALSA: control: Don't access controls outside of protected regions (Lars-Peter Clausen)  [Orabug: 19817785]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - ALSA: control: Fix replacing user controls (Lars-Peter Clausen)  [Orabug: 19817747]  {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655}
        - kvm: iommu: fix the third parameter of kvm_iommu_put_pages (CVE-2014-3601) (Michael S. Tsirkin)  [Orabug: 19817646]  {CVE-2014-3601}
        - net: sctp: inherit auth_capable on INIT collisions (Daniel Borkmann)  [Orabug: 19816067]  {CVE-2014-5077}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:44">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:22.075-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:27.430-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:13.425-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:34892 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:32.858-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:55.477-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-44.1.3.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:126466"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-44.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:126494"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-44.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:126718"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-44.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:126722"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-44.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:126512"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-44.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:126755"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-44.1.3.el6uek" test_ref="oval:org.mitre.oval:tst:126848"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26512" version="5" class="patch">
      <metadata>
        <title>ELSA-2013-2542 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kernel-uek</product>
          <product>mlnx_en</product>
          <product>ofa</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
          <product>kernel-uek-headers</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-2542.html" ref_id="ELSA-2013-2542"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6544" ref_id="CVE-2012-6544"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2206" ref_id="CVE-2013-2206"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2232" ref_id="CVE-2013-2232"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2237" ref_id="CVE-2013-2237"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2851" ref_id="CVE-2013-2851"/>
        <description>kernel-uek
[2.6.32-400.29.3uek]
- block: do not pass disk names as format strings (Jerry Snitselaar) [Orabug: 17230124] {CVE-2013-2851}
- af_key: initialize satype in key_notify_policy_flush() (Nicolas Dichtel) [Orabug: 17370765] {CVE-2013-2237}
- Bluetooth: L2CAP - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17371054] {CVE-2012-6544}
- Bluetooth: HCI - Fix info leak in getsockopt(HCI_FILTER) (Mathias Krause) [Orabug: 17371072] {CVE-2012-6544}
- ipv6: ip6_sk_dst_check() must not assume ipv6 dst (Eric Dumazet) [Orabug: 17371079] {CVE-2013-2232}
- sctp: Use correct sideffect command in duplicate cookie handling (Vlad Yasevich) [Orabug: 17371121] {CVE-2013-2206}
- sctp: deal with multiple COOKIE_ECHO chunks (Max Matveev) [Orabug: 17372129] {CVE-2013-2206}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:16">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T18:03:14.235-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:25.844-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:12.564-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:128834 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:23.730-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:53.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:128563"/>
            <criterion comment="mlnx_en-2.6.32-400.29.3.el5uek is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:128825"/>
            <criterion comment="ofa-2.6.32-400.29.3.el5uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128632"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:128314"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:128403"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:128435"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:129153"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:129150"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.3.el5uek" test_ref="oval:org.mitre.oval:tst:129067"/>
            <criterion comment="mlnx_en-2.6.32-400.29.3.el5uekdebug is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:129148"/>
            <criterion comment="ofa-2.6.32-400.29.3.el5uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128452"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:128543"/>
            <criterion comment="mlnx_en-2.6.32-400.29.3.el6uek is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128834"/>
            <criterion comment="ofa-2.6.32-400.29.3.el6uek is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:129078"/>
            <criterion comment="kernel-uek-debug is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:129115"/>
            <criterion comment="kernel-uek-debug-devel is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:128854"/>
            <criterion comment="kernel-uek-devel is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:128734"/>
            <criterion comment="kernel-uek-doc is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:129111"/>
            <criterion comment="kernel-uek-firmware is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:128886"/>
            <criterion comment="kernel-uek-headers is earlier than 0:2.6.32-400.29.3.el6uek" test_ref="oval:org.mitre.oval:tst:129170"/>
            <criterion comment="mlnx_en-2.6.32-400.29.3.el6uekdebug is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:128796"/>
            <criterion comment="ofa-2.6.32-400.29.3.el6uekdebug is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:128540"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26511" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1473 -- spice-server security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>spice-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1473.html" ref_id="ELSA-2013-1473"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4282" ref_id="CVE-2013-4282"/>
        <description>[0.12.0-12.5]
- Fix issue with error-handling of RSA_private_decrypt() in previous patch
  Related: CVE-2013-4282

[0.12.0-12.el6_4.4]
- Fix buffer overflow when decrypting client SPICE ticket
  Resolves: CVE-2013-4282</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:23:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:59:05.989-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:25.532-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:12.327-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:19:21.238-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:19:21.238-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="spice-server is earlier than 0:0.12.0-12.el6_4.5" test_ref="oval:org.mitre.oval:tst:128754"/>
          <criterion comment="spice-server-devel is earlier than 0:0.12.0-12.el6_4.5" test_ref="oval:org.mitre.oval:tst:128770"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26508" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1620 -- xorg-x11-server security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1620.html" ref_id="ELSA-2013-1620"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1940" ref_id="CVE-2013-1940"/>
        <description>[1.13.0-23]
- Fix root window damage reports when Xinerama is active (#919165)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:26">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:27.252-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:25.175-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:12.068-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:128480"/>
          <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:128497"/>
          <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:128449"/>
          <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:128374"/>
          <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:128326"/>
          <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:127900"/>
          <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:128473"/>
          <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:128159"/>
          <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:128050"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26478" version="3" class="patch">
      <metadata>
        <title>ELSA-2013-1536 -- libguestfs security, bug fix, and enhancement update (moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libguestfs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1536.html" ref_id="ELSA-2013-1536"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4419" ref_id="CVE-2013-4419"/>
        <description>[1:1.20.11-2]
- Fix CVE-2013-4419: insecure temporary directory handling for
  guestfish's network socket
  resolves: rhbz#1019737</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:32.646-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:24.776-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:11.767-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libguestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:128333"/>
          <criterion comment="libguestfs-devel is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:128398"/>
          <criterion comment="libguestfs-java is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:128405"/>
          <criterion comment="libguestfs-java-devel is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:127859"/>
          <criterion comment="libguestfs-javadoc is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:128378"/>
          <criterion comment="libguestfs-tools is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:127782"/>
          <criterion comment="libguestfs-tools-c is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:128320"/>
          <criterion comment="ocaml-libguestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:128493"/>
          <criterion comment="ocaml-libguestfs-devel is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:128487"/>
          <criterion comment="perl-Sys-Guestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:128484"/>
          <criterion comment="python-libguestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:127985"/>
          <criterion comment="ruby-libguestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:128454"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26472" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0429 -- tomcat6 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0429.html" ref_id="ELSA-2014-0429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0050" ref_id="CVE-2014-0050"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4322" ref_id="CVE-2013-4322"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4286" ref_id="CVE-2013-4286"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3544" ref_id="CVE-2012-3544"/>
        <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that when Tomcat processed a series of HTTP requests in which
at least one request contained either multiple content-length headers, or
one content-length header with a chunked transfer-encoding header, Tomcat
would incorrectly handle the request. A remote attacker could use this flaw
to poison a web cache, perform cross-site scripting (XSS) attacks, or
obtain sensitive information from other requests. (CVE-2013-4286)

It was discovered that the fix for CVE-2012-3544 did not properly resolve a
denial of service flaw in the way Tomcat processed chunk extensions and
trailing headers in chunked requests. A remote attacker could use this flaw
to send an excessively long request that, when processed by Tomcat, could
consume network bandwidth, CPU, and memory on the Tomcat server. Note that
chunked transfer encoding is enabled by default. (CVE-2013-4322)

A denial of service flaw was found in the way Apache Commons FileUpload
handled small-sized buffers used by MultipartStream. A remote attacker
could use this flaw to create a malformed Content-Type header for a
multipart request, causing JBoss Web to enter an infinite loop when
processing such an incoming request. (CVE-2014-0050)

All Tomcat users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:53">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:03.636-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:00:51.394-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:33.112-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:34:00.244-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:34:00.244-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="tomcat6 RPM is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:124687"/>
          <criterion comment="tomcat6-admin-webapps RPM is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:124865"/>
          <criterion comment="tomcat6-docs-webapp RPM is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:124887"/>
          <criterion comment="tomcat6-el-2.1-api RPM is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:124577"/>
          <criterion comment="tomcat6-javadoc RPM is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:124745"/>
          <criterion comment="tomcat6-jsp-2.1-api RPM is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:124327"/>
          <criterion comment="tomcat6-lib RPM is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:124851"/>
          <criterion comment="tomcat6-servlet-2.5-api RPM is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:123915"/>
          <criterion comment="tomcat6-webapps RPM is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:124846"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26440" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1813 -- php53 and php security update (critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1813.html" ref_id="ELSA-2013-1813"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6420" ref_id="CVE-2013-6420"/>
        <description>[5.3.3-27]
- add security fix for CVE-2013-6420</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:48.238-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:23.600-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:10.847-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:07:10.976-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:07:10.976-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php53 is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:127642"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128359"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128275"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128392"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128068"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128177"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128364"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128402"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128251"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:127621"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:127973"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128382"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128401"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128343"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128155"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128100"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128281"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128293"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128075"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:127463"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:128199"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128229"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:127689"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128380"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128385"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128032"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128340"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128339"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128282"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128302"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128303"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128194"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:127833"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128289"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128252"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128341"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128239"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128025"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128244"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128156"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:127962"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128145"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128395"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:127619"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128327"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128222"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128311"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:128381"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26425" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013-1868 -- xorg-x11-server security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2013-1868.html" ref_id="ELSA-2013-1868"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6424" ref_id="CVE-2013-6424"/>
        <description>[1.13.0-23.1]
- Fix root window damage reports when Xinerama is active (#919165)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:51:39.229-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:22.710-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:10.052-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T11:24:56.670-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T11:24:56.670-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:127293"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:127955"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:128269"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:128279"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:127753"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:127804"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:128077"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.0.1.el5_10.2" test_ref="oval:org.mitre.oval:tst:128294"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127945"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:128109"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127850"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127946"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:128265"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127820"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:128045"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127316"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:127794"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26409" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0151 -- wget security and bug fix update (low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>wget</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0151.html" ref_id="ELSA-2014-0151"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2252" ref_id="CVE-2010-2252"/>
        <description>[1.12-1.11]
- Add --trust-server-names option to fix CVE-2010-2252 (#833831)

[1.12-1.10]
- Build wget again with partial RELRO. LDFLAGS changed due to openssl rebase.

[1.12-1.9]
- Fix wget to recognize certificates with alternative names (#1060113)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:22:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:30.863-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:20.849-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:09.425-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T12:07:02.013-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T12:07:02.013-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="wget is earlier than 0:1.12-1.11.el6_5" test_ref="oval:org.mitre.oval:tst:128098"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26365" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3034 -- Unbreakable Enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>dtrace-modules-headers</product>
          <product>dtrace-modules-provider-headers</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3034.html" ref_id="ELSA-2014-3034"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0196" ref_id="CVE-2014-0196"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2309" ref_id="CVE-2014-2309"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0049" ref_id="CVE-2014-0049"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0038" ref_id="CVE-2014-0038"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4587" ref_id="CVE-2013-4587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7266" ref_id="CVE-2013-7266"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6885" ref_id="CVE-2013-6885"/>
        <description>kernel-uek 

[3.8.13-35.el6uek] 

- n_tty: Fix n_tty_write crash when echoing in raw mode (Peter Hurley) [Orabug: 18754908] {CVE-2014-0196} {CVE-2014-0196}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:44:20.587-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:18.704-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:08.275-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126687 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:31.289-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:52.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-35.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:126687"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-35.el6uek" test_ref="oval:org.mitre.oval:tst:126689"/>
          <criterion comment="dtrace-modules-headers is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:127576"/>
          <criterion comment="dtrace-modules-provider-headers is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:127643"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-35.el6uek" test_ref="oval:org.mitre.oval:tst:127400"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-35.el6uek" test_ref="oval:org.mitre.oval:tst:127118"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-35.el6uek" test_ref="oval:org.mitre.oval:tst:127285"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-35.el6uek" test_ref="oval:org.mitre.oval:tst:127622"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-35.el6uek" test_ref="oval:org.mitre.oval:tst:127485"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26359" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3052 -- unbreakable enterprise kernel security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dtrace-modules</product>
          <product>kernel-uek</product>
          <product>kernel-uek-debug</product>
          <product>kernel-uek-debug-devel</product>
          <product>kernel-uek-devel</product>
          <product>kernel-uek-doc</product>
          <product>kernel-uek-firmware</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3052.html" ref_id="ELSA-2014-3052"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3144" ref_id="CVE-2014-3144"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3145" ref_id="CVE-2014-3145"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2706" ref_id="CVE-2014-2706"/>
        <description>kernel-uek
[3.8.13-35.3.3.el7uek]
- filter: prevent nla extensions to peek beyond the end of the message (Mathias Krause)  [Orabug: 19315781]  {CVE-2014-3144} {CVE-2014-3145}
- mac80211: fix AP powersave TX vs. wakeup race (Emmanuel Grumbach)  [Orabug: 19316457]  {CVE-2014-2706}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:21:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:29:30.352-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:18.039-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:07.840-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:127081 - Corrected package names in objects and versions in states." date="2015-02-26T18:36:00.989-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T18:48:29.097-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:52.056-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="dtrace-modules-3.8.13-35.3.3.el6uek is earlier than 0:0.4.3-4.el6" test_ref="oval:org.mitre.oval:tst:127081"/>
          <criterion comment="kernel-uek is earlier than 0:3.8.13-35.3.3.el6uek" test_ref="oval:org.mitre.oval:tst:126391"/>
          <criterion comment="kernel-uek-debug is earlier than 0:3.8.13-35.3.3.el6uek" test_ref="oval:org.mitre.oval:tst:127127"/>
          <criterion comment="kernel-uek-debug-devel is earlier than 0:3.8.13-35.3.3.el6uek" test_ref="oval:org.mitre.oval:tst:126926"/>
          <criterion comment="kernel-uek-devel is earlier than 0:3.8.13-35.3.3.el6uek" test_ref="oval:org.mitre.oval:tst:127182"/>
          <criterion comment="kernel-uek-doc is earlier than 0:3.8.13-35.3.3.el6uek" test_ref="oval:org.mitre.oval:tst:126727"/>
          <criterion comment="kernel-uek-firmware is earlier than 0:3.8.13-35.3.3.el6uek" test_ref="oval:org.mitre.oval:tst:126852"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26310" version="3" class="patch">
      <metadata>
        <title>ELSA-2014-1031 -- 389-ds-base security update (important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1031.html" ref_id="ELSA-2014-1031"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3562" ref_id="CVE-2014-3562"/>
        <description>[1.2.11.15-34]
        - Release 1.2.11.15-34
        - Resolves: #1123861
          EMBARGOED CVE-2014-3562 unauthenticated information disclosure [rhel-6.5.z] (DS 616, BZ 1123477)</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-05T10:20:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-11-05T17:20:18.198-05:00">DRAFT</status_change>
            <status_change date="2014-11-24T04:00:17.284-05:00">INTERIM</status_change>
            <status_change date="2014-12-15T04:00:07.520-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="389-ds-base is earlier than 0:1.2.11.15-34.el6_5" test_ref="oval:org.mitre.oval:tst:126993"/>
            <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-34.el6_5" test_ref="oval:org.mitre.oval:tst:127065"/>
            <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-34.el6_5" test_ref="oval:org.mitre.oval:tst:126681"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="389-ds-base is earlier than 0:1.3.1.6-26.el7_0" test_ref="oval:org.mitre.oval:tst:126385"/>
            <criterion comment="389-ds-base-devel is earlier than 0:1.3.1.6-26.el7_0" test_ref="oval:org.mitre.oval:tst:126918"/>
            <criterion comment="389-ds-base-libs is earlier than 0:1.3.1.6-26.el7_0" test_ref="oval:org.mitre.oval:tst:126907"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26189" version="5" class="patch">
      <metadata>
        <title>ELSA-2014-3073 -- Unbreakable Enterprise kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>kernel-uek</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-3073.html" ref_id="ELSA-2014-3073"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917" ref_id="CVE-2014-3917"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0205" ref_id="CVE-2014-0205"/>
        <description>kernel-uek
[2.6.32-400.36.8.el6uek]
- auditsc: audit_krule mask accesses need bounds checking (Andy 
Lutomirski)  [Orabug: 19590638]  {CVE-2014-3917}
- futex: Fix errors in nested key ref-counting (Darren Hart)  [Orabug: 
19590443]  {CVE-2014-0205}</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-01T10:21:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:35:19.030-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:00:33.902-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:29.167-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:124515 - Corrected package names in objects and versions in states." date="2015-02-26T18:54:00.627-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2015-02-26T19:18:40.076-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:00:50.156-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124678"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124667"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124747"/>
            <criterion comment="kernel-uek-headers RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124583"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124859"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124850"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.32-400.36.8.el6uek" test_ref="oval:org.mitre.oval:tst:124939"/>
            <criterion comment="ofa-2.6.32-400.36.8.el6uek RPM is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:124869"/>
            <criterion comment="ofa-2.6.32-400.36.8.el6uekdebug RPM is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:124913"/>
            <criterion comment="mlnx_en-2.6.32-400.36.8.el6uek RPM is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:124773"/>
            <criterion comment="mlnx_en-2.6.32-400.36.8.el6uekdebug RPM is earlier than 0:1.5.7-0.1" test_ref="oval:org.mitre.oval:tst:124794"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-uek RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124951"/>
            <criterion comment="kernel-uek-debug RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124408"/>
            <criterion comment="kernel-uek-debug-devel RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124766"/>
            <criterion comment="kernel-uek-headers RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124460"/>
            <criterion comment="kernel-uek-devel RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124375"/>
            <criterion comment="kernel-uek-doc RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124017"/>
            <criterion comment="kernel-uek-firmware RPM is earlier than 0:2.6.32-400.36.8.el5uek" test_ref="oval:org.mitre.oval:tst:124889"/>
            <criterion comment="ofa-2.6.32-400.36.8.el5uek RPM is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:124515"/>
            <criterion comment="ofa-2.6.32-400.36.8.el5uekdebug RPM is earlier than 0:1.5.1-4.0.58" test_ref="oval:org.mitre.oval:tst:124479"/>
            <criterion comment="mlnx_en-2.6.32-400.36.8.el5uek RPM is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:124934"/>
            <criterion comment="mlnx_en-2.6.32-400.36.8.el5uekdebug RPM is earlier than 0:1.5.7-2" test_ref="oval:org.mitre.oval:tst:124921"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26179" version="6" class="patch">
      <metadata>
        <title>ELSA-2014-1634 -- java-1.6.0-openjdk security and bug fix update</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 7</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-1634.html" ref_id="ELSA-2014-1634"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6457" ref_id="CVE-2014-6457"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6502" ref_id="CVE-2014-6502"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6504" ref_id="CVE-2014-6504"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6506" ref_id="CVE-2014-6506"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6511" ref_id="CVE-2014-6511"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6512" ref_id="CVE-2014-6512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6517" ref_id="CVE-2014-6517"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6519" ref_id="CVE-2014-6519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6531" ref_id="CVE-2014-6531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6558" ref_id="CVE-2014-6558"/>
        <description>[1:1.6.0.33-1.13.5.0]

- Update to IcedTea 1.13.5

- Remove upstreamed patches.

- Regenerate add-final-location-rpaths patch against new release.

- Change versioning to match java-1.7.0-openjdk so revisions work.

- Use xz for tarballs to reduce file size.

- No need to explicitly disable system LCMS any more (bug fixed upstream).

- Add icedteasnapshot to setup lines so they work with pre-release tarballs.

- Resolves: rhbz#1148901</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T17:21:19">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:33:18.274-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26179 - Updated patches for Oracle Linux by switching dpkginfo tests to new rpminfo tests." date="2014-10-31T14:02:00.180-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-17T04:00:27.228-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:18.587-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:126306 - Corrected epochs in Oracle Linux Patches" date="2015-07-24T13:44:00.886-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-24T13:45:43.596-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:26.361-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Oracle Linux 5 release section">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126377"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126335"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126343"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126241"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.0.1.el5_11" test_ref="oval:org.mitre.oval:tst:126149"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 6 release section">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125953"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:126306"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:126176"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:126246"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:126297"/>
          </criteria>
        </criteria>
        <criteria comment="Oracle Linux 7 release section">
          <extend_definition comment="Oracle Linux 7.x" definition_ref="oval:org.mitre.oval:def:25183"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126393"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126362"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126469"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126402"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:126251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25183" version="3" class="inventory">
      <metadata>
        <title>Oracle Linux 7.x</title>
        <affected family="unix">
          <platform>Oracle Linux 7</platform>
        </affected>
        <reference ref_id="cpe:/o:oracle:linux:7" source="CPE"/>
        <description>The operating system installed on the system is Oracle Linux 7.x</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-07-23T11:44:52.851-04:00">DRAFT</status_change>
            <status_change date="2014-08-11T04:00:56.441-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:01.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Unix family" test_ref="oval:org.mitre.oval:tst:4424"/>
        <criterion comment="Oracle Linux 7.x is installed" test_ref="oval:org.mitre.oval:tst:115464"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26077" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014-0383 -- samba4 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_url="http://linux.oracle.com/errata/ELSA-2014-0383.html" ref_id="ELSA-2014-0383"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150" ref_id="CVE-2012-6150"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4496" ref_id="CVE-2013-4496"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6442" ref_id="CVE-2013-6442"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

It was found that certain Samba configurations did not enforce the password
lockout mechanism. A remote attacker could use this flaw to perform
password guessing attacks on Samba user accounts. Note: this flaw only
affected Samba when deployed as a Primary Domain Controller.
(CVE-2013-4496)

A flaw was found in Samba&amp;#39;s &amp;quot;smbcacls&amp;quot; command, which is used to set or get
ACLs on SMB file shares. Certain command line options of this command would
incorrectly remove an ACL previously applied on a file or a directory,
leaving the file or directory without the intended ACL. (CVE-2013-6442)

A flaw was found in the way the pam_winbind module handled configurations
that specified a non-existent group as required. An authenticated user
could possibly use this flaw to gain access to a service using pam_winbind
in its PAM configuration when group restriction was intended for access to
the service. (CVE-2012-6150)

Red Hat would like to thank the Samba project for reporting CVE-2013-4496
and CVE-2013-6442, and Sam Richardson for reporting CVE-2012-6150.
Upstream acknowledges Andrew Bartlett as the original reporter of
CVE-2013-4496, and Noel Power as the original reporter of CVE-2013-6442.

All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-29T17:52:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-10T18:20:06.430-04:00">DRAFT</status_change>
            <status_change date="2014-10-27T04:00:26.927-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:24.573-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-10T21:35:11.629-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-10T21:35:11.629-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="samba4 RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124752"/>
          <criterion comment="samba4-client RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:123959"/>
          <criterion comment="samba4-common RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124436"/>
          <criterion comment="samba4-dc RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124328"/>
          <criterion comment="samba4-dc-libs RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124525"/>
          <criterion comment="samba4-devel RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124631"/>
          <criterion comment="samba4-libs RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124705"/>
          <criterion comment="samba4-pidl RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124229"/>
          <criterion comment="samba4-python RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124435"/>
          <criterion comment="samba4-swat RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124342"/>
          <criterion comment="samba4-test RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124022"/>
          <criterion comment="samba4-winbind RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:123835"/>
          <criterion comment="samba4-winbind-clients RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124774"/>
          <criterion comment="samba4-winbind-krb5-locator RPM is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:124573"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25230" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0595: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2014:0595-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0595.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-3466" ref_url="http://linux.oracle.com/cve/CVE-2014-3466.html" source="CVE"/>
        <description>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).
A flaw was found in the way GnuTLS parsed session IDs from ServerHello
messages of the TLS/SSL handshake. A malicious server could use this flaw
to send an excessively long session ID value, which would trigger a buffer
overflow in a connecting TLS/SSL client application using GnuTLS, causing
the client application to crash or, possibly, execute arbitrary code.
(CVE-2014-3466)
Red Hat would like to thank GnuTLS upstream for reporting this issue.
Upstream acknowledges Joonas Kuorilehto of Codenomicon as the original
reporter.
Users of GnuTLS are advised to upgrade to these updated packages, which
correct this issue. For the update to take effect, all applications linked
to the GnuTLS library must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:54.156-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25230 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:01:00.830-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:05.675-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gnutls is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:115348"/>
          <criterion comment="gnutls-guile is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:115200"/>
          <criterion comment="gnutls-devel is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:115408"/>
          <criterion comment="gnutls-utils is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:115489"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25200" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0426: qemu-kvm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu</product>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2014:0426-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0426.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0142" ref_url="http://linux.oracle.com/cve/CVE-2014-0142.html" source="CVE"/>
        <reference ref_id="CVE-2014-0143" ref_url="http://linux.oracle.com/cve/CVE-2014-0143.html" source="CVE"/>
        <reference ref_id="CVE-2014-0144" ref_url="http://linux.oracle.com/cve/CVE-2014-0144.html" source="CVE"/>
        <reference ref_id="CVE-2014-0145" ref_url="http://linux.oracle.com/cve/CVE-2014-0145.html" source="CVE"/>
        <reference ref_id="CVE-2014-0146" ref_url="http://linux.oracle.com/cve/CVE-2014-0146.html" source="CVE"/>
        <reference ref_id="CVE-2014-0147" ref_url="http://linux.oracle.com/cve/CVE-2014-0147.html" source="CVE"/>
        <reference ref_id="CVE-2014-0148" ref_url="http://linux.oracle.com/cve/CVE-2014-0148.html" source="CVE"/>
        <reference ref_id="CVE-2014-0150" ref_url="http://linux.oracle.com/cve/CVE-2014-0150.html" source="CVE"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.
...
All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:51.179-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25200 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:58.572-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:03.806-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:115512"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:115617"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:114671"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:115473"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25198" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0742: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0742-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0742.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1533" ref_url="http://linux.oracle.com/cve/CVE-2014-1533.html" source="CVE"/>
        <reference ref_id="CVE-2014-1538" ref_url="http://linux.oracle.com/cve/CVE-2014-1538.html" source="CVE"/>
        <reference ref_id="CVE-2014-1541" ref_url="http://linux.oracle.com/cve/CVE-2014-1541.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.6.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.6.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:52.351-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25198 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:58.312-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:03.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:115644"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:115405"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25192" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0513: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2014:0513-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0513.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2877" ref_url="http://linux.oracle.com/cve/CVE-2013-2877.html" source="CVE"/>
        <reference ref_id="CVE-2014-0191" ref_url="http://linux.oracle.com/cve/CVE-2014-0191.html" source="CVE"/>
        <description>The libxml2 library is a development toolbox providing the implementation
of various XML standards.
It was discovered that libxml2 loaded external parameter entities even when
entity substitution was disabled. A remote attacker able to provide a
specially crafted XML file to an application linked against libxml2 could
use this flaw to conduct XML External Entity (XXE) attacks, possibly
resulting in a denial of service or an information leak on the system.
(CVE-2014-0191)
An out-of-bounds read flaw was found in the way libxml2 detected the end of
an XML file. A remote attacker could provide a specially crafted XML file
that, when processed by an application linked against libxml2, could cause
the application to crash. (CVE-2013-2877)
The CVE-2014-0191 issue was discovered by Daniel P. Berrange of Red Hat.
All libxml2 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The desktop must be
restarted (log out, then log back in) for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:46:00.275-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25192 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:58.103-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:03.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libxml2 is earlier than 0:2.7.6-14.el6_5.1" test_ref="oval:org.mitre.oval:tst:115631"/>
          <criterion comment="libxml2-devel is earlier than 0:2.7.6-14.el6_5.1" test_ref="oval:org.mitre.oval:tst:115566"/>
          <criterion comment="libxml2-python is earlier than 0:2.7.6-14.el6_5.1" test_ref="oval:org.mitre.oval:tst:115495"/>
          <criterion comment="libxml2-static is earlier than 0:2.7.6-14.el6_5.1" test_ref="oval:org.mitre.oval:tst:115633"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25185" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0508: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2014:0508-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0508.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-0878" ref_url="http://linux.oracle.com/cve/CVE-2014-0878.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>IBM Java SE version 6 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.
This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0461, CVE-2014-2428, CVE-2014-0446, CVE-2014-0452,
CVE-2014-0451, CVE-2014-2423, CVE-2014-2427, CVE-2014-0458, CVE-2014-2414,
CVE-2014-2412, CVE-2014-2409, CVE-2014-0460, CVE-2013-6954, CVE-2013-6629,
CVE-2014-2401, CVE-2014-0449, CVE-2014-0453, CVE-2014-2398, CVE-2014-1876,
CVE-2014-2420)
All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 6 SR16 release. All running instances
of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:49.765-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25185 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:56.530-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:02.017-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115494"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115319"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115604"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115658"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115515"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115393"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115654"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115481"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115385"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115225"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115554"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115547"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115499"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115616"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115573"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25175" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0561: curl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2014:0561-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0561.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0015" ref_url="http://linux.oracle.com/cve/CVE-2014-0015.html" source="CVE"/>
        <reference ref_id="CVE-2014-0138" ref_url="http://linux.oracle.com/cve/CVE-2014-0138.html" source="CVE"/>
        <description>cURL provides the libcurl library and a command line tool for downloading
files from servers using various protocols, including HTTP, FTP, and LDAP.
It was found that libcurl could incorrectly reuse existing connections for
requests that should have used different or no authentication credentials,
when using one of the following protocols: HTTP(S) with NTLM
authentication, LDAP(S), SCP, or SFTP. If an application using the libcurl
library connected to a remote server with certain authentication
credentials, this flaw could cause other requests to use those same
credentials. (CVE-2014-0015, CVE-2014-0138)
Red Hat would like to thank the cURL project for reporting these issues.
Upstream acknowledges Paras Sethia as the original reporter of
CVE-2014-0015 and Yehezkel Horowitz for discovering the security impact of
this issue, and Steve Holme as the original reporter of CVE-2014-0138.
This update also fixes the following bugs:
* Previously, the libcurl library was closing a network socket without
first terminating the SSL connection using the socket. This resulted in a
write after close and consequent leakage of memory dynamically allocated by
the SSL library. An upstream patch has been applied on libcurl to fix this
bug. As a result, the write after close no longer happens, and the SSL
library no longer leaks memory. (BZ#1092479)
* Previously, the libcurl library did not implement a non-blocking SSL
handshake, which negatively affected performance of applications based on
libcurl's multi API. To fix this bug, the non-blocking SSL handshake has
been implemented by libcurl. With this update, libcurl's multi API
immediately returns the control back to the application whenever it cannot
read/write data from/to the underlying network socket. (BZ#1092480)
* Previously, the curl package could not be rebuilt from sources due to an
expired cookie in the upstream test-suite, which runs during the build. An
upstream patch has been applied to postpone the expiration date of the
cookie, which makes it possible to rebuild the package from sources again.
(BZ#1092486)
* Previously, the libcurl library attempted to authenticate using Kerberos
whenever such an authentication method was offered by the server. This
caused problems when the server offered multiple authentication methods and
Kerberos was not the selected one. An upstream patch has been applied on
libcurl to fix this bug. Now libcurl no longer uses Kerberos authentication
if another authentication method is selected. (BZ#1096797)
All curl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications that use libcurl have to be restarted for this update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:51.655-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25175 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:55.921-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:01.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="curl is earlier than 0:7.19.7-37.el6_5.3" test_ref="oval:org.mitre.oval:tst:115641"/>
          <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_5.3" test_ref="oval:org.mitre.oval:tst:115626"/>
          <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_5.3" test_ref="oval:org.mitre.oval:tst:115420"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25171" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0625: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2014:0625-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0625.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-5298" ref_url="http://linux.oracle.com/cve/CVE-2010-5298.html" source="CVE"/>
        <reference ref_id="CVE-2014-0195" ref_url="http://linux.oracle.com/cve/CVE-2014-0195.html" source="CVE"/>
        <reference ref_id="CVE-2014-0198" ref_url="http://linux.oracle.com/cve/CVE-2014-0198.html" source="CVE"/>
        <reference ref_id="CVE-2014-0221" ref_url="http://linux.oracle.com/cve/CVE-2014-0221.html" source="CVE"/>
        <reference ref_id="CVE-2014-0224" ref_url="http://linux.oracle.com/cve/CVE-2014-0224.html" source="CVE"/>
        <reference ref_id="CVE-2014-3470" ref_url="http://linux.oracle.com/cve/CVE-2014-3470.html" source="CVE"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.
It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)
Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433
A buffer overflow flaw was found in the way OpenSSL handled invalid DTLS
packet fragments. A remote attacker could possibly use this flaw to execute
arbitrary code on a DTLS client or server. (CVE-2014-0195)
Multiple flaws were found in the way OpenSSL handled read and write buffers
when the SSL_MODE_RELEASE_BUFFERS mode was enabled. A TLS/SSL client or
server using OpenSSL could crash or unexpectedly drop connections when
processing certain SSL traffic. (CVE-2010-5298, CVE-2014-0198)
A denial of service flaw was found in the way OpenSSL handled certain DTLS
ServerHello requests. A specially crafted DTLS handshake packet could cause
a DTLS client using OpenSSL to crash. (CVE-2014-0221)
A NULL pointer dereference flaw was found in the way OpenSSL performed
anonymous Elliptic Curve Diffie Hellman (ECDH) key exchange. A specially
crafted handshake packet could cause a TLS/SSL client that has the
anonymous ECDH cipher suite enabled to crash. (CVE-2014-3470)
Red Hat would like to thank the OpenSSL project for reporting these issues.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of CVE-2014-0224, Juri Aedla as the original reporter of CVE-2014-0195,
Imre Rad of Search-Lab as the original reporter of CVE-2014-0221, and Felix
Grobert and Ivan Fratric of Google as the original reporters of
CVE-2014-3470.
All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:47.874-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25171 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:55.293-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:01.419-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:115360"/>
          <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:115340"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:115474"/>
          <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:115376"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25170" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0745: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0745-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0745.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0531" ref_url="http://linux.oracle.com/cve/CVE-2014-0531.html" source="CVE"/>
        <reference ref_id="CVE-2014-0532" ref_url="http://linux.oracle.com/cve/CVE-2014-0532.html" source="CVE"/>
        <reference ref_id="CVE-2014-0533" ref_url="http://linux.oracle.com/cve/CVE-2014-0533.html" source="CVE"/>
        <reference ref_id="CVE-2014-0534" ref_url="http://linux.oracle.com/cve/CVE-2014-0534.html" source="CVE"/>
        <reference ref_id="CVE-2014-0535" ref_url="http://linux.oracle.com/cve/CVE-2014-0535.html" source="CVE"/>
        <reference ref_id="CVE-2014-0536" ref_url="http://linux.oracle.com/cve/CVE-2014-0536.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-16,
listed in the References section.
Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0534, CVE-2014-0535, CVE-2014-0536)
Multiple flaws in flash-plugin could allow an attacker to conduct
cross-site scripting (XSS) attacks if a victim were tricked into visiting a
specially crafted web page. (CVE-2014-0531, CVE-2014-0532, CVE-2014-0533)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.378.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:49.334-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25170 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:54.797-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:01.075-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.378-1.el5" test_ref="oval:org.mitre.oval:tst:114686"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.378-1.el6" test_ref="oval:org.mitre.oval:tst:115556"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25169" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0560: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2014:0560-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0560.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0179" ref_url="http://linux.oracle.com/cve/CVE-2014-0179.html" source="CVE"/>
        <description>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In 
addition, libvirt provides tools for remote management of virtualized
systems. 
It was found that libvirt passes the XML_PARSE_NOENT flag when parsing XML
documents using the libxml2 library, in which case all XML entities in the
parsed documents are expanded. A user able to force libvirtd to parse an
XML document with an entity pointing to a special file that blocks on read
access could use this flaw to cause libvirtd to hang indefinitely,
resulting in a denial of service on the system. (CVE-2014-0179)
Red Hat would like to thank the upstream Libvirt project for reporting this
issue. Upstream acknowledges Daniel P. Berrange and Richard Jones as the
original reporters.
This update also fixes the following bugs:
* When hot unplugging a virtual CPU (vCPU), libvirt kept a pointer to
already freed memory if the vCPU was pinned to a host CPU. Consequently,
when reading the CPU pinning information, libvirt terminated unexpectedly
due to an attempt to access this memory. This update ensures that libvirt
releases the pointer to the previously allocated memory when a vCPU is
being hot unplugged, and it no longer crashes in this situation.
(BZ#1091206)
* Previously, libvirt passed an incorrect argument to the "tc" command when
setting quality of service (QoS) on a network interface controller (NIC).
As a consequence, QoS was applied only to IP traffic. With this update,
libvirt constructs the "tc" command correctly so that QoS is applied to all
traffic as expected. (BZ#1096806)
* When using the sanlock daemon for managing access to shared storage,
libvirt expected all QEMU domains to be registered with sanlock. However,
if a QEMU domain was started prior to enabling sanlock, the domain was not
registered with sanlock. Consequently, migration of a virtual machine (VM)
from such a QEMU domain failed with a libvirt error. With this update,
libvirt verifies whether a QEMU domain process is registered with sanlock
before it starts working with the domain, ensuring that migration of
virtual machines works as expected. (BZ#1097227)
All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, libvirtd will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:53.702-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25169 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:54.619-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:00.931-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:115527"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:115647"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:115653"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:115649"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:115648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25168" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0596: libtasn1 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtasn1</product>
        </affected>
        <reference ref_id="ELSA-2014:0596-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0596.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-3467" ref_url="http://linux.oracle.com/cve/CVE-2014-3467.html" source="CVE"/>
        <reference ref_id="CVE-2014-3468" ref_url="http://linux.oracle.com/cve/CVE-2014-3468.html" source="CVE"/>
        <reference ref_id="CVE-2014-3469" ref_url="http://linux.oracle.com/cve/CVE-2014-3469.html" source="CVE"/>
        <description>The libtasn1 library provides Abstract Syntax Notation One (ASN.1) parsing
and structures management, and Distinguished Encoding Rules (DER) encoding
and decoding functions.
It was discovered that the asn1_get_bit_der() function of the libtasn1
library incorrectly reported the length of ASN.1-encoded data. Specially
crafted ASN.1 input could cause an application using libtasn1 to perform
an out-of-bounds access operation, causing the application to crash or,
possibly, execute arbitrary code. (CVE-2014-3468)
Multiple incorrect buffer boundary check issues were discovered in
libtasn1. Specially crafted ASN.1 input could cause an application using
libtasn1 to crash. (CVE-2014-3467)
Multiple NULL pointer dereference flaws were found in libtasn1's
asn1_read_value() function. Specially crafted ASN.1 input could cause an
application using libtasn1 to crash, if the application used the
aforementioned function in a certain way. (CVE-2014-3469)
Red Hat would like to thank GnuTLS upstream for reporting these issues.
All libtasn1 users are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the libtasn1 library must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:46:00.706-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25168 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:54.324-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:00.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libtasn1 is earlier than 0:2.3-6.el6_5" test_ref="oval:org.mitre.oval:tst:115642"/>
          <criterion comment="libtasn1-tools is earlier than 0:2.3-6.el6_5" test_ref="oval:org.mitre.oval:tst:115480"/>
          <criterion comment="libtasn1-devel is earlier than 0:2.3-6.el6_5" test_ref="oval:org.mitre.oval:tst:115125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25131" version="4" class="patch">
      <metadata>
        <title>ELSA-2012:0688: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:0688-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0688.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0779" ref_url="http://linux.oracle.com/cve/CVE-2012-0779.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed on the Adobe security page APSB12-09, listed in
the References section. Specially-crafted SWF content could cause
flash-plugin to crash or, potentially, execute arbitrary code when a victim
loads a page containing the specially-crafted SWF content. (CVE-2012-0779)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.3.183.19.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:46:01.057-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25131 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:51.986-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:59.689-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="flash-plugin is earlier than 0:10.3.183.19-1.el6" test_ref="oval:org.mitre.oval:tst:115459"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25106" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0626: openssl097a and openssl098e security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference ref_id="ELSA-2014:0626-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0626.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0224" ref_url="http://linux.oracle.com/cve/CVE-2014-0224.html" source="CVE"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.
It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)
Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433
Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of this issue.
All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:53.445-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25106 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:50.521-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:58.488-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="openssl097a is earlier than 0:0.9.7a-12.el5_10.1" test_ref="oval:org.mitre.oval:tst:115670"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="openssl098e is earlier than 0:0.9.8e-18.el6_5.2" test_ref="oval:org.mitre.oval:tst:115424"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25057" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0597: squid security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference ref_id="ELSA-2014:0597-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0597.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0128" ref_url="http://linux.oracle.com/cve/CVE-2014-0128.html" source="CVE"/>
        <description>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.
A denial of service flaw was found in the way Squid processed certain HTTPS
requests when the SSL Bump feature was enabled. A remote attacker could
send specially crafted requests that could cause Squid to crash.
(CVE-2014-0128)
Red Hat would like to thank the Squid project for reporting this issue.
Upstream acknowledges Mathias Fischer and Fabian Hugelshofer from Open
Systems AG as the original reporters.
All squid users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the squid service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:52.659-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25057 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:46.465-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:56.735-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="squid is earlier than 7:3.1.10-20.el6_5.3" test_ref="oval:org.mitre.oval:tst:115457"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25005" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0741: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2014:0741-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0741.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1533" ref_url="http://linux.oracle.com/cve/CVE-2014-1533.html" source="CVE"/>
        <reference ref_id="CVE-2014-1538" ref_url="http://linux.oracle.com/cve/CVE-2014-1538.html" source="CVE"/>
        <reference ref_id="CVE-2014-1541" ref_url="http://linux.oracle.com/cve/CVE-2014-1541.html" source="CVE"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.6.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.6.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:59.127-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25005 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:43.145-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:55.401-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:115530"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.6.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:115118"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115529"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115454"/>
            <criterion comment="xulrunner is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115428"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24953" version="3" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 7</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:7"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 7.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:29.153-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:42.013-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:58.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 7 is installed" test_ref="oval:org.mitre.oval:tst:115398"/>
        <criterion negate="true" comment="Oracle Linux 7.x is installed" test_ref="oval:org.mitre.oval:tst:115342"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24919" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0743: qemu-kvm security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2014:0743-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0743.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4148" ref_url="http://linux.oracle.com/cve/CVE-2013-4148.html" source="CVE"/>
        <reference ref_id="CVE-2013-4151" ref_url="http://linux.oracle.com/cve/CVE-2013-4151.html" source="CVE"/>
        <reference ref_id="CVE-2013-4535" ref_url="http://linux.oracle.com/cve/CVE-2013-4535.html" source="CVE"/>
        <reference ref_id="CVE-2013-4536" ref_url="http://linux.oracle.com/cve/CVE-2013-4536.html" source="CVE"/>
        <reference ref_id="CVE-2013-4541" ref_url="http://linux.oracle.com/cve/CVE-2013-4541.html" source="CVE"/>
        <reference ref_id="CVE-2013-4542" ref_url="http://linux.oracle.com/cve/CVE-2013-4542.html" source="CVE"/>
        <reference ref_id="CVE-2013-6399" ref_url="http://linux.oracle.com/cve/CVE-2013-6399.html" source="CVE"/>
        <reference ref_id="CVE-2014-0182" ref_url="http://linux.oracle.com/cve/CVE-2014-0182.html" source="CVE"/>
        <reference ref_id="CVE-2014-2894" ref_url="http://linux.oracle.com/cve/CVE-2014-2894.html" source="CVE"/>
        <reference ref_id="CVE-2014-3461" ref_url="http://linux.oracle.com/cve/CVE-2014-3461.html" source="CVE"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.
Multiple buffer overflow, input validation, and out-of-bounds write flaws
were found in the way the virtio, virtio-net, virtio-scsi, and usb drivers
of QEMU handled state loading after migration. A user able to alter the
savevm data (either on the disk or over the wire during migration) could
use either of these flaws to corrupt QEMU process memory on the
(destination) host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2013-4148, CVE-2013-4151, CVE-2013-4535, CVE-2013-4536, CVE-2013-4541,
CVE-2013-4542, CVE-2013-6399, CVE-2014-0182, CVE-2014-3461)
An out-of-bounds memory access flaw was found in the way QEMU's IDE device
driver handled the execution of SMART EXECUTE OFFLINE commands.
A privileged guest user could use this flaw to corrupt QEMU process memory
on the host, which could potentially result in arbitrary code execution on
the host with the privileges of the QEMU process. (CVE-2014-2894)
The CVE-2013-4148, CVE-2013-4151, CVE-2013-4535, CVE-2013-4536,
CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182, and
CVE-2014-3461 issues were discovered by Michael S. Tsirkin of Red Hat,
Anthony Liguori, and Michael Roth.
This update also fixes the following bugs:
* Previously, under certain circumstances, libvirt failed to start guests
which used a non-zero PCI domain and SR-IOV Virtual Functions (VFs), and
returned the following error message:
Can't assign device inside non-zero PCI segment as this KVM module doesn't
support it.
This update fixes this issue and guests using the aforementioned
configuration no longer fail to start. (BZ#1099941)
* Due to an incorrect initialization of the cpus_sts bitmap, which holds
the enablement status of a vCPU, libvirt could fail to start a guest with
an unusual vCPU topology (for example, a guest with three cores and two
sockets). With this update, the initialization of cpus_sts has been
corrected, and libvirt no longer fails to start the aforementioned guests.
(BZ#1100575)
All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:55.876-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24919 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:37.414-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:53.025-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:115442"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:115152"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:115223"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:115582"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24881" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0509: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2014:0509-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0509.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0878" ref_url="http://linux.oracle.com/cve/CVE-2014-0878.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <description>IBM J2SE version 5.0 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.
This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-2427, CVE-2014-2412,
CVE-2014-0460, CVE-2013-6629, CVE-2014-2401, CVE-2014-0453, CVE-2014-2398,
CVE-2014-1876)
All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM J2SE 5.0 SR16-FP6 release. All running
instances of IBM Java must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:56.950-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24881 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:32.885-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:50.747-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115365"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114847"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115584"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115419"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115083"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115506"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115282"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115330"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115148"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115490"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115555"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115400"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115578"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115630"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115607"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24851" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0747: python-jinja2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python-jinja2</product>
        </affected>
        <reference ref_id="ELSA-2014:0747-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0747.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1402" ref_url="http://linux.oracle.com/cve/CVE-2014-1402.html" source="CVE"/>
        <description>Jinja2 is a template engine written in pure Python. It provides a
Django-inspired, non-XML syntax but supports inline expressions and an
optional sandboxed environment.
It was discovered that Jinja2 did not properly handle bytecode cache files
stored in the system's temporary directory. A local attacker could use this
flaw to alter the output of an application using Jinja2 and
FileSystemBytecodeCache, and potentially execute arbitrary code with the
privileges of that application. (CVE-2014-1402)
All python-jinja2 users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. For the update to
take effect, all applications using python-jinja2 must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:54.494-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24851 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:32.499-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:50.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="python-jinja2 is earlier than 0:2.2.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:114954"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24843" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0429: tomcat6 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference ref_id="ELSA-2014:0429-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0429.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4286" ref_url="http://linux.oracle.com/cve/CVE-2013-4286.html" source="CVE"/>
        <reference ref_id="CVE-2013-4322" ref_url="http://linux.oracle.com/cve/CVE-2013-4322.html" source="CVE"/>
        <reference ref_id="CVE-2014-0050" ref_url="http://linux.oracle.com/cve/CVE-2014-0050.html" source="CVE"/>
        <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.
It was found that when Tomcat processed a series of HTTP requests in which
at least one request contained either multiple content-length headers, or
one content-length header with a chunked transfer-encoding header, Tomcat
would incorrectly handle the request. A remote attacker could use this flaw
to poison a web cache, perform cross-site scripting (XSS) attacks, or
obtain sensitive information from other requests. (CVE-2013-4286)
It was discovered that the fix for CVE-2012-3544 did not properly resolve a
denial of service flaw in the way Tomcat processed chunk extensions and
trailing headers in chunked requests. A remote attacker could use this flaw
to send an excessively long request that, when processed by Tomcat, could
consume network bandwidth, CPU, and memory on the Tomcat server. Note that
chunked transfer encoding is enabled by default. (CVE-2013-4322)
A denial of service flaw was found in the way Apache Commons FileUpload
handled small-sized buffers used by MultipartStream. A remote attacker
could use this flaw to create a malformed Content-Type header for a
multipart request, causing JBoss Web to enter an infinite loop when
processing such an incoming request. (CVE-2014-0050)
All Tomcat users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:36.123-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:41.936-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:56.106-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24843 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:21.869-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:43.630-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:114059"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:114290"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:114031"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113755"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:114324"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113860"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:114044"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:114106"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113920"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24775" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0383: samba4 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference ref_id="ELSA-2014:0383-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0383.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6150" ref_url="http://linux.oracle.com/cve/CVE-2012-6150.html" source="CVE"/>
        <reference ref_id="CVE-2013-4496" ref_url="http://linux.oracle.com/cve/CVE-2013-4496.html" source="CVE"/>
        <reference ref_id="CVE-2013-6442" ref_url="http://linux.oracle.com/cve/CVE-2013-6442.html" source="CVE"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.
It was found that certain Samba configurations did not enforce the password
lockout mechanism. A remote attacker could use this flaw to perform
password guessing attacks on Samba user accounts. Note: this flaw only
affected Samba when deployed as a Primary Domain Controller.
(CVE-2013-4496)
A flaw was found in Samba's "smbcacls" command, which is used to set or get
ACLs on SMB file shares. Certain command line options of this command would
incorrectly remove an ACL previously applied on a file or a directory,
leaving the file or directory without the intended ACL. (CVE-2013-6442)
A flaw was found in the way the pam_winbind module handled configurations
that specified a non-existent group as required. An authenticated user
could possibly use this flaw to gain access to a service using pam_winbind
in its PAM configuration when group restriction was intended for access to
the service. (CVE-2012-6150)
Red Hat would like to thank the Samba project for reporting CVE-2013-4496
and CVE-2013-6442, and Sam Richardson for reporting CVE-2012-6150.
Upstream acknowledges Andrew Bartlett as the original reporter of
CVE-2013-4496, and Noel Power as the original reporter of CVE-2013-6442.
All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:33.472-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:38.205-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:51.590-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24775 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:15.148-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:41.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="samba4-python is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:114079"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:114203"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:114274"/>
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:114165"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113613"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113723"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113384"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113739"/>
          <criterion comment="samba4 is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113977"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:114222"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:114279"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:114208"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:114234"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113979"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24767" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0486: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2014:0486-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0486.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-0878" ref_url="http://linux.oracle.com/cve/CVE-2014-0878.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>IBM Java SE version 7 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.
This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0461, CVE-2014-0455, CVE-2014-2428, CVE-2014-0448,
CVE-2014-0454, CVE-2014-0446, CVE-2014-0452, CVE-2014-0451, CVE-2014-2402,
CVE-2014-2423, CVE-2014-2427, CVE-2014-0458, CVE-2014-2414, CVE-2014-2412,
CVE-2014-2409, CVE-2014-0460, CVE-2013-6954, CVE-2013-6629, CVE-2014-2401,
CVE-2014-0449, CVE-2014-0459, CVE-2014-0453, CVE-2014-2398, CVE-2014-1876,
CVE-2014-2420)
All users of java-1.7.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 7 SR7 release. All running instances
of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:57.777-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24767 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:28.846-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:47.744-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115406"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115057"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115090"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115035"/>
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115590"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115268"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115579"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115669"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115502"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115449"/>
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115549"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115321"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24759" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0413: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2014:0413-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0413.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0432" ref_url="http://linux.oracle.com/cve/CVE-2014-0432.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2422" ref_url="http://linux.oracle.com/cve/CVE-2014-2422.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)
All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:34.967-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:36.162-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:50.327-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24759 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:33.722-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:39.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113278"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114098"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113617"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113573"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113805"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113763"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114219"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114226"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113404"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114209"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113971"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24739" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0414: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2014:0414-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0414.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2437" ref_url="http://linux.oracle.com/cve/CVE-2013-2437.html" source="CVE"/>
        <reference ref_id="CVE-2013-2442" ref_url="http://linux.oracle.com/cve/CVE-2013-2442.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2451" ref_url="http://linux.oracle.com/cve/CVE-2013-2451.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2464" ref_url="http://linux.oracle.com/cve/CVE-2013-2464.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2466" ref_url="http://linux.oracle.com/cve/CVE-2013-2466.html" source="CVE"/>
        <reference ref_id="CVE-2013-2468" ref_url="http://linux.oracle.com/cve/CVE-2013-2468.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <reference ref_id="CVE-2013-3743" ref_url="http://linux.oracle.com/cve/CVE-2013-3743.html" source="CVE"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5776" ref_url="http://linux.oracle.com/cve/CVE-2013-5776.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5787" ref_url="http://linux.oracle.com/cve/CVE-2013-5787.html" source="CVE"/>
        <reference ref_id="CVE-2013-5789" ref_url="http://linux.oracle.com/cve/CVE-2013-5789.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5801" ref_url="http://linux.oracle.com/cve/CVE-2013-5801.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5812" ref_url="http://linux.oracle.com/cve/CVE-2013-5812.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5818" ref_url="http://linux.oracle.com/cve/CVE-2013-5818.html" source="CVE"/>
        <reference ref_id="CVE-2013-5819" ref_url="http://linux.oracle.com/cve/CVE-2013-5819.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5824" ref_url="http://linux.oracle.com/cve/CVE-2013-5824.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5831" ref_url="http://linux.oracle.com/cve/CVE-2013-5831.html" source="CVE"/>
        <reference ref_id="CVE-2013-5832" ref_url="http://linux.oracle.com/cve/CVE-2013-5832.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5843" ref_url="http://linux.oracle.com/cve/CVE-2013-5843.html" source="CVE"/>
        <reference ref_id="CVE-2013-5848" ref_url="http://linux.oracle.com/cve/CVE-2013-5848.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <reference ref_id="CVE-2013-5852" ref_url="http://linux.oracle.com/cve/CVE-2013-5852.html" source="CVE"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5887" ref_url="http://linux.oracle.com/cve/CVE-2013-5887.html" source="CVE"/>
        <reference ref_id="CVE-2013-5888" ref_url="http://linux.oracle.com/cve/CVE-2013-5888.html" source="CVE"/>
        <reference ref_id="CVE-2013-5889" ref_url="http://linux.oracle.com/cve/CVE-2013-5889.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5898" ref_url="http://linux.oracle.com/cve/CVE-2013-5898.html" source="CVE"/>
        <reference ref_id="CVE-2013-5899" ref_url="http://linux.oracle.com/cve/CVE-2013-5899.html" source="CVE"/>
        <reference ref_id="CVE-2013-5902" ref_url="http://linux.oracle.com/cve/CVE-2013-5902.html" source="CVE"/>
        <reference ref_id="CVE-2013-5905" ref_url="http://linux.oracle.com/cve/CVE-2013-5905.html" source="CVE"/>
        <reference ref_id="CVE-2013-5906" ref_url="http://linux.oracle.com/cve/CVE-2013-5906.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0375" ref_url="http://linux.oracle.com/cve/CVE-2014-0375.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0387" ref_url="http://linux.oracle.com/cve/CVE-2014-0387.html" source="CVE"/>
        <reference ref_id="CVE-2014-0403" ref_url="http://linux.oracle.com/cve/CVE-2014-0403.html" source="CVE"/>
        <reference ref_id="CVE-2014-0410" ref_url="http://linux.oracle.com/cve/CVE-2014-0410.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0415" ref_url="http://linux.oracle.com/cve/CVE-2014-0415.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0417" ref_url="http://linux.oracle.com/cve/CVE-2014-0417.html" source="CVE"/>
        <reference ref_id="CVE-2014-0418" ref_url="http://linux.oracle.com/cve/CVE-2014-0418.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0424" ref_url="http://linux.oracle.com/cve/CVE-2014-0424.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory pages, listed in the References section.
(CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437,
CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446,
CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452,
CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457,
CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465,
CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-3829, CVE-2013-4002,
CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780,
CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789,
CVE-2013-5790, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803,
CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817,
CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824,
CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832,
CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849,
CVE-2013-5850, CVE-2013-5852, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887,
CVE-2013-5888, CVE-2013-5889, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899,
CVE-2013-5902, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910,
CVE-2013-6629, CVE-2013-6954, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375,
CVE-2014-0376, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411,
CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422,
CVE-2014-0423, CVE-2014-0424, CVE-2014-0428, CVE-2014-0429, CVE-2014-0446,
CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453, CVE-2014-0456,
CVE-2014-0457, CVE-2014-0458, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2403, CVE-2014-2409, CVE-2014-2412,
CVE-2014-2414, CVE-2014-2420, CVE-2014-2421, CVE-2014-2423, CVE-2014-2427,
CVE-2014-2428)
All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 75 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:27.291-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:28.976-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:41.984-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24739 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:27.074-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:33.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114114"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113753"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113881"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114212"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114326"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113905"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114325"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114102"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114227"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114091"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114156"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114320"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24738" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0431: virt-viewer bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>virt-viewer</product>
        </affected>
        <reference ref_id="ELSA-2014:0431-02" ref_url="http://linux.oracle.com/errata/ELSA-2014-0431.html" source="VENDOR"/>
        <description>The virt-viewer packages provide Virtual Machine Viewer, which is a lightweight interface for interacting with the graphical display of a virtualized guest. Virtual Machine Viewer uses libvirt and is intended as a replacement for traditional VNC or SPICE clients.
This update fixes the following bug: 
* Prior to this update, Spice determined the scaling of windows incorrectly by using the original desktop size instead of the host screen size. As a consequence, when a guest window was open in Spice, the screen could under some circumstances become blurry. With this update, the guest window scaling has been fixed and this problem no longer occurs. (BZ#1081376)
Users of virt-viewer are advised to upgrade to these updated packages, which fix this bug.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:54.882-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24738 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:28.492-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:47.675-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="virt-viewer is earlier than 0:0.5.6-8.el6_5.1" test_ref="oval:org.mitre.oval:tst:115011"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24708" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0449: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0449-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0449.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1518" ref_url="http://linux.oracle.com/cve/CVE-2014-1518.html" source="CVE"/>
        <reference ref_id="CVE-2014-1523" ref_url="http://linux.oracle.com/cve/CVE-2014-1523.html" source="CVE"/>
        <reference ref_id="CVE-2014-1524" ref_url="http://linux.oracle.com/cve/CVE-2014-1524.html" source="CVE"/>
        <reference ref_id="CVE-2014-1529" ref_url="http://linux.oracle.com/cve/CVE-2014-1529.html" source="CVE"/>
        <reference ref_id="CVE-2014-1530" ref_url="http://linux.oracle.com/cve/CVE-2014-1530.html" source="CVE"/>
        <reference ref_id="CVE-2014-1531" ref_url="http://linux.oracle.com/cve/CVE-2014-1531.html" source="CVE"/>
        <reference ref_id="CVE-2014-1532" ref_url="http://linux.oracle.com/cve/CVE-2014-1532.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)
A use-after-free flaw was found in the way Thunderbird resolved hosts in
certain circumstances. An attacker could use this flaw to crash Thunderbird
or, potentially, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2014-1532)
An out-of-bounds read flaw was found in the way Thunderbird decoded JPEG
images. Loading an email or a web page containing a specially crafted JPEG
image could cause Thunderbird to crash. (CVE-2014-1523)
A flaw was found in the way Thunderbird handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith and Jesse
Schwartzentrube as the original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.5.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:32.909-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:25.672-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:39.401-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24708 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:21.599-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:31.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:114236"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114183"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24691" version="14" class="patch">
      <metadata>
        <title>ELSA-2014:0342: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference ref_id="ELSA-2014:0342-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0342.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6336" ref_url="http://linux.oracle.com/cve/CVE-2013-6336.html" source="CVE"/>
        <reference ref_id="CVE-2013-6337" ref_url="http://linux.oracle.com/cve/CVE-2013-6337.html" source="CVE"/>
        <reference ref_id="CVE-2013-6338" ref_url="http://linux.oracle.com/cve/CVE-2013-6338.html" source="CVE"/>
        <reference ref_id="CVE-2013-6339" ref_url="http://linux.oracle.com/cve/CVE-2013-6339.html" source="CVE"/>
        <reference ref_id="CVE-2013-6340" ref_url="http://linux.oracle.com/cve/CVE-2013-6340.html" source="CVE"/>
        <reference ref_id="CVE-2013-7112" ref_url="http://linux.oracle.com/cve/CVE-2013-7112.html" source="CVE"/>
        <reference ref_id="CVE-2013-7114" ref_url="http://linux.oracle.com/cve/CVE-2013-7114.html" source="CVE"/>
        <reference ref_id="CVE-2014-2281" ref_url="http://linux.oracle.com/cve/CVE-2014-2281.html" source="CVE"/>
        <reference ref_id="CVE-2014-2283" ref_url="http://linux.oracle.com/cve/CVE-2014-2283.html" source="CVE"/>
        <reference ref_id="CVE-2014-2299" ref_url="http://linux.oracle.com/cve/CVE-2014-2299.html" source="CVE"/>
        <description>Wireshark is a network protocol analyzer. It is used to capture and browse
the traffic running on a computer network.
Two flaws were found in Wireshark. If Wireshark read a malformed packet off
a network or opened a malicious dump file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2014-2281,
CVE-2014-2299)
Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2013-6336, CVE-2013-6337, CVE-2013-6338,
CVE-2013-6339, CVE-2013-6340, CVE-2014-2283, CVE-2013-7112, CVE-2013-7114)
All Wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Wireshark must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:31.247-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:39.418-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24691 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:28.903-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="wireshark-gnome is earlier than 0:1.8.10-7.el6_5" test_ref="oval:org.mitre.oval:tst:113732"/>
          <criterion comment="wireshark is earlier than 0:1.8.10-7.el6_5" test_ref="oval:org.mitre.oval:tst:113738"/>
          <criterion comment="wireshark-devel is earlier than 0:1.8.10-7.el6_5" test_ref="oval:org.mitre.oval:tst:113699"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24647" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0380: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0380-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0380.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0506" ref_url="http://linux.oracle.com/cve/CVE-2014-0506.html" source="CVE"/>
        <reference ref_id="CVE-2014-0507" ref_url="http://linux.oracle.com/cve/CVE-2014-0507.html" source="CVE"/>
        <reference ref_id="CVE-2014-0508" ref_url="http://linux.oracle.com/cve/CVE-2014-0508.html" source="CVE"/>
        <reference ref_id="CVE-2014-0509" ref_url="http://linux.oracle.com/cve/CVE-2014-0509.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-09,
listed in the References section.
Two flaws were found in the way flash-plugin displayed certain SWF content.
An attacker could use these flaws to create a specially crafted SWF file
that would cause flash-plugin to crash or, potentially, execute arbitrary
code when the victim loaded a page containing the malicious SWF content.
(CVE-2014-0506, CVE-2014-0507)
A flaw in flash-plugin could allow an attacker to obtain sensitive
information if a victim were tricked into visiting a specially crafted web
page. (CVE-2014-0508)
A flaw in flash-plugin could allow an attacker to conduct cross-site
scripting (XSS) attacks if a victim were tricked into visiting a specially
crafted web page. (CVE-2014-0509)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.350.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:36.633-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:19.516-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:35.487-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24647 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:27.868-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:28.017-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.350-1.el6" test_ref="oval:org.mitre.oval:tst:113729"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24610" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0414: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2014:0414-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0414.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2437" ref_url="http://linux.oracle.com/cve/CVE-2013-2437.html" source="CVE"/>
        <reference ref_id="CVE-2013-2442" ref_url="http://linux.oracle.com/cve/CVE-2013-2442.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2451" ref_url="http://linux.oracle.com/cve/CVE-2013-2451.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2464" ref_url="http://linux.oracle.com/cve/CVE-2013-2464.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2466" ref_url="http://linux.oracle.com/cve/CVE-2013-2466.html" source="CVE"/>
        <reference ref_id="CVE-2013-2468" ref_url="http://linux.oracle.com/cve/CVE-2013-2468.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <reference ref_id="CVE-2013-3743" ref_url="http://linux.oracle.com/cve/CVE-2013-3743.html" source="CVE"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5776" ref_url="http://linux.oracle.com/cve/CVE-2013-5776.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5787" ref_url="http://linux.oracle.com/cve/CVE-2013-5787.html" source="CVE"/>
        <reference ref_id="CVE-2013-5789" ref_url="http://linux.oracle.com/cve/CVE-2013-5789.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5801" ref_url="http://linux.oracle.com/cve/CVE-2013-5801.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5812" ref_url="http://linux.oracle.com/cve/CVE-2013-5812.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5818" ref_url="http://linux.oracle.com/cve/CVE-2013-5818.html" source="CVE"/>
        <reference ref_id="CVE-2013-5819" ref_url="http://linux.oracle.com/cve/CVE-2013-5819.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5824" ref_url="http://linux.oracle.com/cve/CVE-2013-5824.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5831" ref_url="http://linux.oracle.com/cve/CVE-2013-5831.html" source="CVE"/>
        <reference ref_id="CVE-2013-5832" ref_url="http://linux.oracle.com/cve/CVE-2013-5832.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5843" ref_url="http://linux.oracle.com/cve/CVE-2013-5843.html" source="CVE"/>
        <reference ref_id="CVE-2013-5848" ref_url="http://linux.oracle.com/cve/CVE-2013-5848.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <reference ref_id="CVE-2013-5852" ref_url="http://linux.oracle.com/cve/CVE-2013-5852.html" source="CVE"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5887" ref_url="http://linux.oracle.com/cve/CVE-2013-5887.html" source="CVE"/>
        <reference ref_id="CVE-2013-5888" ref_url="http://linux.oracle.com/cve/CVE-2013-5888.html" source="CVE"/>
        <reference ref_id="CVE-2013-5889" ref_url="http://linux.oracle.com/cve/CVE-2013-5889.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5898" ref_url="http://linux.oracle.com/cve/CVE-2013-5898.html" source="CVE"/>
        <reference ref_id="CVE-2013-5899" ref_url="http://linux.oracle.com/cve/CVE-2013-5899.html" source="CVE"/>
        <reference ref_id="CVE-2013-5902" ref_url="http://linux.oracle.com/cve/CVE-2013-5902.html" source="CVE"/>
        <reference ref_id="CVE-2013-5905" ref_url="http://linux.oracle.com/cve/CVE-2013-5905.html" source="CVE"/>
        <reference ref_id="CVE-2013-5906" ref_url="http://linux.oracle.com/cve/CVE-2013-5906.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0375" ref_url="http://linux.oracle.com/cve/CVE-2014-0375.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0387" ref_url="http://linux.oracle.com/cve/CVE-2014-0387.html" source="CVE"/>
        <reference ref_id="CVE-2014-0403" ref_url="http://linux.oracle.com/cve/CVE-2014-0403.html" source="CVE"/>
        <reference ref_id="CVE-2014-0410" ref_url="http://linux.oracle.com/cve/CVE-2014-0410.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0415" ref_url="http://linux.oracle.com/cve/CVE-2014-0415.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0417" ref_url="http://linux.oracle.com/cve/CVE-2014-0417.html" source="CVE"/>
        <reference ref_id="CVE-2014-0418" ref_url="http://linux.oracle.com/cve/CVE-2014-0418.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0424" ref_url="http://linux.oracle.com/cve/CVE-2014-0424.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory pages, listed in the References section.
(CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437,
CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446,
CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452,
CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457,
CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465,
CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-3829, CVE-2013-4002,
CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780,
CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789,
CVE-2013-5790, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803,
CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817,
CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824,
CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832,
CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849,
CVE-2013-5850, CVE-2013-5852, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887,
CVE-2013-5888, CVE-2013-5889, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899,
CVE-2013-5902, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910,
CVE-2013-6629, CVE-2013-6954, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375,
CVE-2014-0376, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411,
CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422,
CVE-2014-0423, CVE-2014-0424, CVE-2014-0428, CVE-2014-0429, CVE-2014-0446,
CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453, CVE-2014-0456,
CVE-2014-0457, CVE-2014-0458, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2403, CVE-2014-2409, CVE-2014-2412,
CVE-2014-2414, CVE-2014-2420, CVE-2014-2421, CVE-2014-2423, CVE-2014-2427,
CVE-2014-2428)
All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 75 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:40.312-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:07.857-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:28.115-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24610 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:25.586-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:06:44.834-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:06:44.834-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114081"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114116"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113751"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114255"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114259"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113644"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114223"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114276"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114113"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113978"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114278"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114243"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24586" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0413: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2014:0413-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0413.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0432" ref_url="http://linux.oracle.com/cve/CVE-2014-0432.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2422" ref_url="http://linux.oracle.com/cve/CVE-2014-2422.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)
All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:34.854-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:03.062-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:25.533-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24586 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:29.962-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:05:37.446-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:05:37.446-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113800"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114265"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113633"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113954"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114254"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114101"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114315"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114056"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114311"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114166"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114159"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24573" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0475: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2014:0475-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0475.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6383" ref_url="http://linux.oracle.com/cve/CVE-2013-6383.html" source="CVE"/>
        <reference ref_id="CVE-2014-0077" ref_url="http://linux.oracle.com/cve/CVE-2014-0077.html" source="CVE"/>
        <reference ref_id="CVE-2014-2523" ref_url="http://linux.oracle.com/cve/CVE-2014-2523.html" source="CVE"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.
* A flaw was found in the way the Linux kernel's netfilter connection
tracking implementation for Datagram Congestion Control Protocol (DCCP)
packets used the skb_header_pointer() function. A remote attacker could use
this flaw to send a specially crafted DCCP packet to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-2523,
Important)
* A flaw was found in the way the Linux kernel's Adaptec RAID controller
(aacraid) checked permissions of compat IOCTLs. A local attacker could use
this flaw to bypass intended security restrictions. (CVE-2013-6383,
Moderate)
* A flaw was found in the way the handle_rx() function handled large
network packets when mergeable buffers were disabled. A privileged guest
user could use this flaw to crash the host or corrupt QEMU process memory
on the host, which could potentially result in arbitrary code execution on
the host with the privileges of the QEMU process. (CVE-2014-0077, Moderate)
The CVE-2014-0077 issue was discovered by Michael S. Tsirkin of Red Hat.
This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.
All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:59.874-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24573 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:24.203-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:44.693-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="python-perf is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115367"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115221"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115143"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115304"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115232"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114949"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115458"/>
          <criterion comment="kernel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115366"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115586"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115324"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115572"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115625"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:115451"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24559" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0330: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2014:0330-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0330.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6150" ref_url="http://linux.oracle.com/cve/CVE-2012-6150.html" source="CVE"/>
        <reference ref_id="CVE-2013-4496" ref_url="http://linux.oracle.com/cve/CVE-2013-4496.html" source="CVE"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.
It was found that certain Samba configurations did not enforce the password
lockout mechanism. A remote attacker could use this flaw to perform
password guessing attacks on Samba user accounts. Note: this flaw only
affected Samba when deployed as a Primary Domain Controller.
(CVE-2013-4496)
A flaw was found in the way the pam_winbind module handled configurations
that specified a non-existent group as required. An authenticated user
could possibly use this flaw to gain access to a service using pam_winbind
in its PAM configuration when group restriction was intended for access to
the service. (CVE-2012-6150)
Red Hat would like to thank the Samba project for reporting CVE-2013-4496
and Sam Richardson for reporting CVE-2012-6150. Upstream acknowledges
Andrew Bartlett as the original reporter of CVE-2013-4496.
All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:25.822-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:38.940-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24559 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:27.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113767"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113750"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113491"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113328"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113791"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113386"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113782"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-swat is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113510"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113847"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112879"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113777"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113679"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113580"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112958"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113387"/>
            <criterion comment="samba is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113629"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113690"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113821"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113721"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24542" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0370: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2014:0370-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0370.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6438" ref_url="http://linux.oracle.com/cve/CVE-2013-6438.html" source="CVE"/>
        <reference ref_id="CVE-2014-0098" ref_url="http://linux.oracle.com/cve/CVE-2014-0098.html" source="CVE"/>
        <description>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.
It was found that the mod_dav module did not correctly strip leading white
space from certain elements in a parsed XML. In certain httpd
configurations that use the mod_dav module (for example when using the
mod_dav_svn module), a remote attacker could send a specially crafted DAV
request that would cause the httpd child process to crash or, possibly,
allow the attacker to execute arbitrary code with the privileges of the
"apache" user. (CVE-2013-6438)
A buffer over-read flaw was found in the httpd mod_log_config module.
In configurations where cookie logging is enabled (on Red Hat Enterprise
Linux it is disabled by default), a remote attacker could use this flaw to
crash the httpd child process via an HTTP request with a malformed cookie
header. (CVE-2014-0098)
All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:30.598-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:38.642-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24542 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:26.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="httpd-tools is earlier than 0:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113769"/>
          <criterion comment="mod_ssl is earlier than 1:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113409"/>
          <criterion comment="httpd is earlier than 0:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113360"/>
          <criterion comment="httpd-devel is earlier than 0:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113877"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113673"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24511" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0304: mutt security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mutt</product>
        </affected>
        <reference ref_id="ELSA-2014:0304-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0304.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0467" ref_url="http://linux.oracle.com/cve/CVE-2014-0467.html" source="CVE"/>
        <description>Mutt is a text-mode mail user agent.
A heap-based buffer overflow flaw was found in the way mutt processed
certain email headers. A remote attacker could use this flaw to send an
email with specially crafted headers that, when processed, could cause mutt
to crash or, potentially, execute arbitrary code with the permissions of
the user running mutt. (CVE-2014-0467)
All mutt users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue. All running instances of
mutt must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:29.600-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:38.319-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24511 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:26.353-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="mutt is earlier than 5:1.5.20-4.20091214hg736b6a.el6_5" test_ref="oval:org.mitre.oval:tst:113640"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24509" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0348: xalan-j2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xalan-j2</product>
        </affected>
        <reference ref_id="ELSA-2014:0348-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0348.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0107" ref_url="http://linux.oracle.com/cve/CVE-2014-0107.html" source="CVE"/>
        <description>Xalan-Java is an XSLT processor for transforming XML documents into HTML,
text, or other XML document types.
It was found that the secure processing feature of Xalan-Java had
insufficient restrictions defined for certain properties and features.
A remote attacker able to provide Extensible Stylesheet Language
Transformations (XSLT) content to be processed by an application using
Xalan-Java could use this flaw to bypass the intended constraints of the
secure processing feature. Depending on the components available in the
classpath, this could lead to arbitrary remote code execution in the
context of the application server running the application that uses
Xalan-Java. (CVE-2014-0107)
All xalan-j2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:27.651-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:38.176-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24509 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:26.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113758"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113745"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113674"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113471"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113845"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113714"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113631"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113744"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113691"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113547"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24508" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0246: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2014:0246-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0246.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0092" ref_url="http://linux.oracle.com/cve/CVE-2014-0092.html" source="CVE"/>
        <description>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).
It was discovered that GnuTLS did not correctly handle certain errors that
could occur during the verification of an X.509 certificate, causing it to
incorrectly report a successful verification. An attacker could use this
flaw to create a specially crafted certificate that could be accepted by
GnuTLS as valid for a site chosen by the attacker. (CVE-2014-0092)
The CVE-2014-0092 issue was discovered by Nikos Mavrogiannopoulos of the
Red Hat Security Technologies Team.
Users of GnuTLS are advised to upgrade to these updated packages, which
correct this issue. For the update to take effect, all applications linked
to the GnuTLS library must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:30.293-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:38.046-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24508 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:26.163-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gnutls-devel is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:113299"/>
          <criterion comment="gnutls-utils is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:113376"/>
          <criterion comment="gnutls is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:113481"/>
          <criterion comment="gnutls-guile is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:113320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24494" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0330: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2014:0330-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0330.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6150" ref_url="http://linux.oracle.com/cve/CVE-2012-6150.html" source="CVE"/>
        <reference ref_id="CVE-2013-4496" ref_url="http://linux.oracle.com/cve/CVE-2013-4496.html" source="CVE"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.
It was found that certain Samba configurations did not enforce the password
lockout mechanism. A remote attacker could use this flaw to perform
password guessing attacks on Samba user accounts. Note: this flaw only
affected Samba when deployed as a Primary Domain Controller.
(CVE-2013-4496)
A flaw was found in the way the pam_winbind module handled configurations
that specified a non-existent group as required. An authenticated user
could possibly use this flaw to gain access to a service using pam_winbind
in its PAM configuration when group restriction was intended for access to
the service. (CVE-2012-6150)
Red Hat would like to thank the Samba project for reporting CVE-2013-4496
and Sam Richardson for reporting CVE-2012-6150. Upstream acknowledges
Andrew Bartlett as the original reporter of CVE-2013-4496.
All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:42.019-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:37.592-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24494 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:25.693-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:05:02.158-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:05:02.158-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113587"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113390"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113575"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113253"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113449"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113318"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113526"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113227"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-swat is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113210"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113238"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113243"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113544"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113411"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113021"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113139"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113452"/>
            <criterion comment="samba is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113614"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113379"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113196"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113603"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24493" version="11" class="patch">
      <metadata>
        <title>ELSA-2014:0211: postgresql84 and postgresql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2014:0211-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0211.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0060" ref_url="http://linux.oracle.com/cve/CVE-2014-0060.html" source="CVE"/>
        <reference ref_id="CVE-2014-0061" ref_url="http://linux.oracle.com/cve/CVE-2014-0061.html" source="CVE"/>
        <reference ref_id="CVE-2014-0062" ref_url="http://linux.oracle.com/cve/CVE-2014-0062.html" source="CVE"/>
        <reference ref_id="CVE-2014-0063" ref_url="http://linux.oracle.com/cve/CVE-2014-0063.html" source="CVE"/>
        <reference ref_id="CVE-2014-0064" ref_url="http://linux.oracle.com/cve/CVE-2014-0064.html" source="CVE"/>
        <reference ref_id="CVE-2014-0065" ref_url="http://linux.oracle.com/cve/CVE-2014-0065.html" source="CVE"/>
        <reference ref_id="CVE-2014-0066" ref_url="http://linux.oracle.com/cve/CVE-2014-0066.html" source="CVE"/>
        <description>PostgreSQL is an advanced object-relational database management system
(DBMS).
Multiple stack-based buffer overflow flaws were found in the date/time
implementation of PostgreSQL. An authenticated database user could provide
a specially crafted date/time value that, when processed, could cause
PostgreSQL to crash or, potentially, execute arbitrary code with the
permissions of the user running PostgreSQL. (CVE-2014-0063)
Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in various type input functions in PostgreSQL. An authenticated
database user could possibly use these flaws to crash PostgreSQL or,
potentially, execute arbitrary code with the permissions of the user
running PostgreSQL. (CVE-2014-0064)
Multiple potential buffer overflow flaws were found in PostgreSQL.
An authenticated database user could possibly use these flaws to crash
PostgreSQL or, potentially, execute arbitrary code with the permissions of
the user running PostgreSQL. (CVE-2014-0065)
It was found that granting an SQL role to a database user in a PostgreSQL
database without specifying the "ADMIN" option allowed the grantee to
remove other users from their granted role. An authenticated database user
could use this flaw to remove a user from an SQL role which they were
granted access to. (CVE-2014-0060)
A flaw was found in the validator functions provided by PostgreSQL's
procedural languages (PLs). An authenticated database user could possibly
use this flaw to escalate their privileges. (CVE-2014-0061)
A race condition was found in the way the CREATE INDEX command performed
multiple independent lookups of a table that had to be indexed. An
authenticated database user could possibly use this flaw to escalate their
privileges. (CVE-2014-0062)
It was found that the chkpass extension of PostgreSQL did not check the
return value of the crypt() function. An authenticated database user could
possibly use this flaw to crash PostgreSQL via a null pointer dereference.
(CVE-2014-0066)
Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Noah Misch as the original reporter of
CVE-2014-0060 and CVE-2014-0063, Heikki Linnakangas and Noah Misch as the
original reporters of CVE-2014-0064, Peter Eisentraut and Jozef Mlich as
the original reporters of CVE-2014-0065, Andres Freund as the original
reporter of CVE-2014-0061, Robert Haas and Andres Freund as the original
reporters of CVE-2014-0062, and Honza Horak and Bruce Momjian as the
original reporters of CVE-2014-0066.
These updated packages upgrade PostgreSQL to version 8.4.20, which fixes
these issues as well as several non-security issues. Refer to the
PostgreSQL Release Notes for a full list of changes:
http://www.postgresql.org/docs/8.4/static/release-8-4-19.html
http://www.postgresql.org/docs/8.4/static/release-8-4-20.html
All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:28.851-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:37.142-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24493 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:25.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113342"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112768"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113485"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113256"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113662"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113627"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113378"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113697"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113496"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113704"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113398"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113676"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113756"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113440"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113706"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113604"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113665"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113265"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113474"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113747"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113761"/>
            <criterion comment="postgresql is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24458" version="14" class="patch">
      <metadata>
        <title>ELSA-2014:0310: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0310-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0310.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1493" ref_url="http://linux.oracle.com/cve/CVE-2014-1493.html" source="CVE"/>
        <reference ref_id="CVE-2014-1497" ref_url="http://linux.oracle.com/cve/CVE-2014-1497.html" source="CVE"/>
        <reference ref_id="CVE-2014-1505" ref_url="http://linux.oracle.com/cve/CVE-2014-1505.html" source="CVE"/>
        <reference ref_id="CVE-2014-1508" ref_url="http://linux.oracle.com/cve/CVE-2014-1508.html" source="CVE"/>
        <reference ref_id="CVE-2014-1509" ref_url="http://linux.oracle.com/cve/CVE-2014-1509.html" source="CVE"/>
        <reference ref_id="CVE-2014-1510" ref_url="http://linux.oracle.com/cve/CVE-2014-1510.html" source="CVE"/>
        <reference ref_id="CVE-2014-1511" ref_url="http://linux.oracle.com/cve/CVE-2014-1511.html" source="CVE"/>
        <reference ref_id="CVE-2014-1512" ref_url="http://linux.oracle.com/cve/CVE-2014-1512.html" source="CVE"/>
        <reference ref_id="CVE-2014-1513" ref_url="http://linux.oracle.com/cve/CVE-2014-1513.html" source="CVE"/>
        <reference ref_id="CVE-2014-1514" ref_url="http://linux.oracle.com/cve/CVE-2014-1514.html" source="CVE"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)
Several information disclosure flaws were found in the way Firefox
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Firefox to crash. (CVE-2014-1497,
CVE-2014-1508, CVE-2014-1505)
A memory corruption flaw was found in the way Firefox rendered certain PDF
files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Firefox or, potentially, execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2014-1509)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.4.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.4.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:29.782-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:36.273-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24458 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:24.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113642"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:113655"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24418" version="14" class="patch">
      <metadata>
        <title>ELSA-2014:0316: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0316-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0316.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1493" ref_url="http://linux.oracle.com/cve/CVE-2014-1493.html" source="CVE"/>
        <reference ref_id="CVE-2014-1497" ref_url="http://linux.oracle.com/cve/CVE-2014-1497.html" source="CVE"/>
        <reference ref_id="CVE-2014-1505" ref_url="http://linux.oracle.com/cve/CVE-2014-1505.html" source="CVE"/>
        <reference ref_id="CVE-2014-1508" ref_url="http://linux.oracle.com/cve/CVE-2014-1508.html" source="CVE"/>
        <reference ref_id="CVE-2014-1509" ref_url="http://linux.oracle.com/cve/CVE-2014-1509.html" source="CVE"/>
        <reference ref_id="CVE-2014-1510" ref_url="http://linux.oracle.com/cve/CVE-2014-1510.html" source="CVE"/>
        <reference ref_id="CVE-2014-1511" ref_url="http://linux.oracle.com/cve/CVE-2014-1511.html" source="CVE"/>
        <reference ref_id="CVE-2014-1512" ref_url="http://linux.oracle.com/cve/CVE-2014-1512.html" source="CVE"/>
        <reference ref_id="CVE-2014-1513" ref_url="http://linux.oracle.com/cve/CVE-2014-1513.html" source="CVE"/>
        <reference ref_id="CVE-2014-1514" ref_url="http://linux.oracle.com/cve/CVE-2014-1514.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)
Several information disclosure flaws were found in the way Thunderbird
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Thunderbird to crash.
(CVE-2014-1497, CVE-2014-1508, CVE-2014-1505)
A memory corruption flaw was found in the way Thunderbird rendered certain
PDF files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Thunderbird or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2014-1509)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.4.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.4.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:28.104-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:34.637-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24418 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:23.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113726"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:113759"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24411" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0412: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2014:0412-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0412.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0432" ref_url="http://linux.oracle.com/cve/CVE-2014-0432.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2422" ref_url="http://linux.oracle.com/cve/CVE-2014-2422.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)
All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:37.606-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:36.766-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:13.691-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24411 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:35.541-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:16.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113800"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114265"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113633"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113954"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114254"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114101"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114315"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114056"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114311"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114166"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114159"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24349" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0448: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0448-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0448.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1518" ref_url="http://linux.oracle.com/cve/CVE-2014-1518.html" source="CVE"/>
        <reference ref_id="CVE-2014-1523" ref_url="http://linux.oracle.com/cve/CVE-2014-1523.html" source="CVE"/>
        <reference ref_id="CVE-2014-1524" ref_url="http://linux.oracle.com/cve/CVE-2014-1524.html" source="CVE"/>
        <reference ref_id="CVE-2014-1529" ref_url="http://linux.oracle.com/cve/CVE-2014-1529.html" source="CVE"/>
        <reference ref_id="CVE-2014-1530" ref_url="http://linux.oracle.com/cve/CVE-2014-1530.html" source="CVE"/>
        <reference ref_id="CVE-2014-1531" ref_url="http://linux.oracle.com/cve/CVE-2014-1531.html" source="CVE"/>
        <reference ref_id="CVE-2014-1532" ref_url="http://linux.oracle.com/cve/CVE-2014-1532.html" source="CVE"/>
        <description>Mozilla Firefox is an open source web browser.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)
A use-after-free flaw was found in the way Firefox resolved hosts in
certain circumstances. An attacker could use this flaw to crash Firefox or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1532)
An out-of-bounds read flaw was found in the way Firefox decoded JPEG
images. Loading a web page containing a specially crafted JPEG image could
cause Firefox to crash. (CVE-2014-1523)
A flaw was found in the way Firefox handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith, and Jesse
Schwartzentrube as the original reporters of these issues.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.5.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Firefox users should upgrade to this updated package, which contains
Firefox version 24.5.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:33.852-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:35.107-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:09.708-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24349 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:28.850-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:14.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:114298"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114015"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24343" version="15" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0316: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0316-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0316.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1493" ref_url="http://linux.oracle.com/cve/CVE-2014-1493.html" source="CVE"/>
        <reference ref_id="CVE-2014-1497" ref_url="http://linux.oracle.com/cve/CVE-2014-1497.html" source="CVE"/>
        <reference ref_id="CVE-2014-1505" ref_url="http://linux.oracle.com/cve/CVE-2014-1505.html" source="CVE"/>
        <reference ref_id="CVE-2014-1508" ref_url="http://linux.oracle.com/cve/CVE-2014-1508.html" source="CVE"/>
        <reference ref_id="CVE-2014-1509" ref_url="http://linux.oracle.com/cve/CVE-2014-1509.html" source="CVE"/>
        <reference ref_id="CVE-2014-1510" ref_url="http://linux.oracle.com/cve/CVE-2014-1510.html" source="CVE"/>
        <reference ref_id="CVE-2014-1511" ref_url="http://linux.oracle.com/cve/CVE-2014-1511.html" source="CVE"/>
        <reference ref_id="CVE-2014-1512" ref_url="http://linux.oracle.com/cve/CVE-2014-1512.html" source="CVE"/>
        <reference ref_id="CVE-2014-1513" ref_url="http://linux.oracle.com/cve/CVE-2014-1513.html" source="CVE"/>
        <reference ref_id="CVE-2014-1514" ref_url="http://linux.oracle.com/cve/CVE-2014-1514.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)
Several information disclosure flaws were found in the way Thunderbird
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Thunderbird to crash.
(CVE-2014-1497, CVE-2014-1508, CVE-2014-1505)
A memory corruption flaw was found in the way Thunderbird rendered certain
PDF files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Thunderbird or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2014-1509)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.4.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.4.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:39.553-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:33.177-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24343 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:23.090-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:03:26.450-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:03:26.450-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113543"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:112954"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24324" version="9" class="patch">
      <metadata>
        <title>ELSA-2014:0376: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2014:0376-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0376.html" source="VENDOR"/>
        <reference source="CESA" ref_id="CESA-2014:0160"/>
        <reference ref_id="CVE-2014-0160" ref_url="http://linux.oracle.com/cve/CVE-2014-0160.html" source="CVE"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.
An information disclosure flaw was found in the way OpenSSL handled TLS and
DTLS Heartbeat Extension packets. A malicious TLS or DTLS client or server
could send a specially crafted TLS or DTLS Heartbeat packet to disclose a
limited portion of memory per request from a connected client or server.
Note that the disclosed portions of memory could potentially include
sensitive information such as private keys. (CVE-2014-0160)
Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges Neel Mehta of Google Security as the original
reporter.
All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-10T22:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2014-04-10T13:30:15.763-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24324 - updated platform tag" date="2014-04-10T13:30:00.686-04:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:24324 - Modified def for Heartbleed Vulenrability CVE-2014-0160 for OEL 6 and CentOS 6" date="2014-04-15T08:10:00.464-04:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </modified>
            <status_change date="2014-05-05T04:00:19.559-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24324 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:22.705-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24324 - added lower bound tests" date="2014-07-02T12:45:00.238-04:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-07-02T12:47:31.048-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:13.683-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criterion comment="CentOS Linux 6.x is installed" test_ref="oval:org.mitre.oval:tst:80900"/>
        </criteria>
        <criteria operator="OR" comment="rpm test">
          <criteria operator="AND" comment="rpm test">
            <criterion comment="openssl-devel is greater than or equal to 1.0.1e-15" test_ref="oval:org.mitre.oval:tst:115294"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:113705"/>
          </criteria>
          <criteria operator="AND" comment="rpm test">
            <criterion comment="openssl is greater than or equal to 1.0.1e-15" test_ref="oval:org.mitre.oval:tst:114659"/>
            <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:113286"/>
          </criteria>
          <criteria operator="AND" comment="rpm test">
            <criterion comment="openssl-static is greater than or equal to 1.0.1e-15" test_ref="oval:org.mitre.oval:tst:115004"/>
            <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:113601"/>
          </criteria>
          <criteria operator="AND" comment="rpm test">
            <criterion comment="openssl-perl is greater than or equal to 1.0.1e-15" test_ref="oval:org.mitre.oval:tst:114982"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:113703"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24315" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0289: flash-plugin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0289-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0289.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0503" ref_url="http://linux.oracle.com/cve/CVE-2014-0503.html" source="CVE"/>
        <reference ref_id="CVE-2014-0504" ref_url="http://linux.oracle.com/cve/CVE-2014-0504.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes two vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security bulletin APSB14-08,
listed in the References section.
A vulnerability was reported that could be used to bypass the same origin
policy. (CVE-2014-0503)
A vulnerability was reported that could be used to read the contents of the
clipboard. (CVE-2014-0504)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.346.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:30.871-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:32.406-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24315 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:22.589-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.346-1.el6" test_ref="oval:org.mitre.oval:tst:113608"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24276" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0406: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0406-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0406.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.
An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)
Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)
Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0455, CVE-2014-0461)
Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, Security, Sound, and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2014-2412, CVE-2014-0451,
CVE-2014-0458, CVE-2014-2423, CVE-2014-0452, CVE-2014-2414, CVE-2014-2402,
CVE-2014-0446, CVE-2014-2413, CVE-2014-0454, CVE-2014-2427, CVE-2014-0459)
Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)
It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)
It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)
It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)
An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)
Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.
All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:31.524-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:31.566-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:05.383-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24276 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:22.069-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:12.406-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:113748"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:114241"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:113884"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:113922"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:114181"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24259" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0321: net-snmp security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>net-snmp</product>
        </affected>
        <reference ref_id="ELSA-2014:0321-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0321.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-2284" ref_url="http://linux.oracle.com/cve/CVE-2014-2284.html" source="CVE"/>
        <description>The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.
A buffer overflow flaw was found in the way the decode_icmp_msg() function
in the ICMP-MIB implementation processed Internet Control Message Protocol
(ICMP) message statistics reported in the /proc/net/snmp file. A remote
attacker could send a message for each ICMP message type, which could
potentially cause the snmpd service to crash when processing the
/proc/net/snmp file. (CVE-2014-2284)
This update also fixes the following bug:
* The snmpd service parses the /proc/diskstats file to track disk usage
statistics for UCD-DISKIO-MIB::diskIOTable. On systems with a large number
of block devices, /proc/diskstats may be large in size and parsing it can
take a non-trivial amount of CPU time. With this update, Net-SNMP
introduces a new option, 'diskio', in the /etc/snmp/snmpd.conf file, which
can be used to explicitly specify devices that should be monitored.
Only these whitelisted devices are then reported in
UCD-DISKIO-MIB::diskIOTable, thus speeding up snmpd on systems with
numerous block devices. (BZ#990674)
All net-snmp users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the snmpd service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:24.830-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:31.161-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24259 - optimisation of Oracle Linux content" date="2014-05-05T18:24:00.075-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-26T04:06:21.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="net-snmp-perl is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113718"/>
          <criterion comment="net-snmp-python is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113681"/>
          <criterion comment="net-snmp-devel is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113346"/>
          <criterion comment="net-snmp-utils is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113680"/>
          <criterion comment="net-snmp-libs is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113175"/>
          <criterion comment="net-snmp is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113579"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24229" version="4" class="patch">
      <metadata>
        <title>ELSA-2014:0496: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0496-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0496.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0510" ref_url="http://linux.oracle.com/cve/CVE-2014-0510.html" source="CVE"/>
        <reference ref_id="CVE-2014-0516" ref_url="http://linux.oracle.com/cve/CVE-2014-0516.html" source="CVE"/>
        <reference ref_id="CVE-2014-0517" ref_url="http://linux.oracle.com/cve/CVE-2014-0517.html" source="CVE"/>
        <reference ref_id="CVE-2014-0518" ref_url="http://linux.oracle.com/cve/CVE-2014-0518.html" source="CVE"/>
        <reference ref_id="CVE-2014-0519" ref_url="http://linux.oracle.com/cve/CVE-2014-0519.html" source="CVE"/>
        <reference ref_id="CVE-2014-0520" ref_url="http://linux.oracle.com/cve/CVE-2014-0520.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-14,
listed in the References section.
Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0510, CVE-2014-0517, CVE-2014-0518, CVE-2014-0519,
CVE-2014-0520)
A flaw in flash-plugin could allow an attacker to bypass the same-origin
policy. (CVE-2014-0516)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.359.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-25T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </submitted>
            <status_change date="2014-07-10T11:45:52.063-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24229 - modified Oracle Linux content" date="2014-07-23T14:34:00.918-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-11T04:00:19.135-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:38.051-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.359-1.el5" test_ref="oval:org.mitre.oval:tst:115417"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.359-1.el6" test_ref="oval:org.mitre.oval:tst:115395"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24206" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0348: xalan-j2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xalan-j2</product>
        </affected>
        <reference ref_id="ELSA-2014:0348-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0348.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0107" ref_url="http://linux.oracle.com/cve/CVE-2014-0107.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:44.537-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:30.136-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:12.606-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24206 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:29.085-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:02:55.186-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:02:55.186-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113588"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112926"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113312"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113423"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112920"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113497"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113407"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:112946"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113514"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113602"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24198" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1452: vino security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference ref_id="ELSA-2013:1452-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1452.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5745" ref_url="http://linux.oracle.com/cve/CVE-2013-5745.html" source="CVE"/>
        <description>The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) via multiple crafted requests during authentication.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:02.040-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:52.667-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:29.908-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24198 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:54.163-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:21.029-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="vino is earlier than 0:2.28.1-9.el6_4" test_ref="oval:org.mitre.oval:tst:112262"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="vino is earlier than 0:2.13.5-10.el5_10" test_ref="oval:org.mitre.oval:tst:112485"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24196" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1869: pixman security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference ref_id="ELSA-2013:1869-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1869.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6425" ref_url="http://linux.oracle.com/cve/CVE-2013-6425.html" source="CVE"/>
        <description>Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:07.883-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:52.592-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:29.801-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24196 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:47.464-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:20.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pixman-devel is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:112381"/>
            <criterion comment="pixman is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:112642"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pixman-devel is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:112846"/>
            <criterion comment="pixman is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:112654"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24193" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0137: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0137-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0137.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0497" ref_url="http://linux.oracle.com/cve/CVE-2014-0497.html" source="CVE"/>
        <description>Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:39.439-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:52.438-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:29.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24193 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.518-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:20.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.336-1.el6" test_ref="oval:org.mitre.oval:tst:112863"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24190" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1582: python security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python</product>
        </affected>
        <reference ref_id="ELSA-2013:1582-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-1582.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4238" ref_url="http://linux.oracle.com/cve/CVE-2013-4238.html" source="CVE"/>
        <description>The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:15.918-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:52.354-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:29.448-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24190 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:44.840-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:20.695-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tkinter is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:112470"/>
          <criterion comment="python-tools is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:112212"/>
          <criterion comment="python-test is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:112138"/>
          <criterion comment="python is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:112473"/>
          <criterion comment="python-libs is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:112255"/>
          <criterion comment="python-devel is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:111857"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24188" version="45" class="patch">
      <metadata>
        <title>ELSA-2014:0136: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2014:0136-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0136.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0417" ref_url="http://linux.oracle.com/cve/CVE-2014-0417.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:41.629-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:51.813-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:29.035-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24188 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:47.066-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:20.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112872"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112327"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112753"/>
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112525"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112705"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112471"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112685"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24186" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1273: spice-gtk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>spice-gtk</product>
        </affected>
        <reference ref_id="ELSA-2013:1273-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1273.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4324" ref_url="http://linux.oracle.com/cve/CVE-2013-4324.html" source="CVE"/>
        <description>spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:00.036-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:51.740-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:28.915-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24186 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:50.177-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:20.275-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="spice-gtk-devel is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:111995"/>
          <criterion comment="spice-glib-devel is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:112264"/>
          <criterion comment="spice-gtk-python is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:112440"/>
          <criterion comment="spice-gtk is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:112442"/>
          <criterion comment="spice-gtk-tools is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:112220"/>
          <criterion comment="spice-glib is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:111983"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24185" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1500: gc security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gc</product>
        </affected>
        <reference ref_id="ELSA-2013:1500-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1500.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2673" ref_url="http://linux.oracle.com/cve/CVE-2012-2673.html" source="CVE"/>
        <description>Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc funtions in malloc.c, and the (3) GC_generic_malloc_ignore_off_page function in mallocx.c in Boehm-Demers-Weiser GC (libgc) before 7.2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:08.948-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:51.670-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:28.807-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24185 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:51.555-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:20.187-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gc-devel is earlier than 0:7.1-12.el6_4" test_ref="oval:org.mitre.oval:tst:111979"/>
          <criterion comment="gc is earlier than 0:7.1-12.el6_4" test_ref="oval:org.mitre.oval:tst:112328"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24184" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0175: piranha security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>piranha</product>
        </affected>
        <reference ref_id="ELSA-2014:0175-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0175.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6492" ref_url="http://linux.oracle.com/cve/CVE-2013-6492.html" source="CVE"/>
        <description>The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:36.789-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:51.608-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:28.703-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24184 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:52.062-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:20.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="piranha is earlier than 0:0.8.6-4.el6_5.2" test_ref="oval:org.mitre.oval:tst:112787"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24183" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:1829: nss, nspr, and nss-util security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference ref_id="ELSA-2013:1829-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1829.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1739" ref_url="http://linux.oracle.com/cve/CVE-2013-1739.html" source="CVE"/>
        <reference ref_id="CVE-2013-1741" ref_url="http://linux.oracle.com/cve/CVE-2013-1741.html" source="CVE"/>
        <reference ref_id="CVE-2013-5605" ref_url="http://linux.oracle.com/cve/CVE-2013-5605.html" source="CVE"/>
        <reference ref_id="CVE-2013-5606" ref_url="http://linux.oracle.com/cve/CVE-2013-5606.html" source="CVE"/>
        <reference ref_id="CVE-2013-5607" ref_url="http://linux.oracle.com/cve/CVE-2013-5607.html" source="CVE"/>
        <description>Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:07.624-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:51.448-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:28.375-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24183 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:49.566-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:19.883-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nspr is earlier than 0:4.10.2-1.el6_5" test_ref="oval:org.mitre.oval:tst:112157"/>
          <criterion comment="nspr-devel is earlier than 0:4.10.2-1.el6_5" test_ref="oval:org.mitre.oval:tst:112694"/>
          <criterion comment="nss-util-devel is earlier than 0:3.15.3-1.el6_5" test_ref="oval:org.mitre.oval:tst:112712"/>
          <criterion comment="nss-util is earlier than 0:3.15.3-1.el6_5" test_ref="oval:org.mitre.oval:tst:112806"/>
          <criterion comment="nss-tools is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:112719"/>
          <criterion comment="nss-devel is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:112579"/>
          <criterion comment="nss-sysinit is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:111997"/>
          <criterion comment="nss is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:112716"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:112548"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24182" version="17" class="patch">
      <metadata>
        <title>ELSA-2014:0015: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2014:0015-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0015.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4353" ref_url="http://linux.oracle.com/cve/CVE-2013-4353.html" source="CVE"/>
        <reference ref_id="CVE-2013-6449" ref_url="http://linux.oracle.com/cve/CVE-2013-6449.html" source="CVE"/>
        <reference ref_id="CVE-2013-6450" ref_url="http://linux.oracle.com/cve/CVE-2013-6450.html" source="CVE"/>
        <description>The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:40.514-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:51.297-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:28.179-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24182 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.662-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:19.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:112818"/>
          <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:112802"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:112756"/>
          <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:112184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24181" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0044: augeas security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>augeas</product>
        </affected>
        <reference ref_id="ELSA-2014:0044-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0044.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6412" ref_url="http://linux.oracle.com/cve/CVE-2013-6412.html" source="CVE"/>
        <description>The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:39.278-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:51.223-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:28.080-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24181 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:50.441-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:19.608-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="augeas-libs is earlier than 0:1.0.0-5.el6_5.1" test_ref="oval:org.mitre.oval:tst:112833"/>
          <criterion comment="augeas is earlier than 0:1.0.0-5.el6_5.1" test_ref="oval:org.mitre.oval:tst:112478"/>
          <criterion comment="augeas-devel is earlier than 0:1.0.0-5.el6_5.1" test_ref="oval:org.mitre.oval:tst:112860"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24180" version="57" class="patch">
      <metadata>
        <title>ELSA-2014:0097: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0097-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0097.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:38.540-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:50.930-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:27.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24180 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:45.464-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:19.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112353"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112681"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112877"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112874"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:112840"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112230"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112495"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112691"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112610"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:112057"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24179" version="37" class="patch">
      <metadata>
        <title>ELSA-2013:1268: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1268-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1268.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1718" ref_url="http://linux.oracle.com/cve/CVE-2013-1718.html" source="CVE"/>
        <reference ref_id="CVE-2013-1722" ref_url="http://linux.oracle.com/cve/CVE-2013-1722.html" source="CVE"/>
        <reference ref_id="CVE-2013-1725" ref_url="http://linux.oracle.com/cve/CVE-2013-1725.html" source="CVE"/>
        <reference ref_id="CVE-2013-1730" ref_url="http://linux.oracle.com/cve/CVE-2013-1730.html" source="CVE"/>
        <reference ref_id="CVE-2013-1732" ref_url="http://linux.oracle.com/cve/CVE-2013-1732.html" source="CVE"/>
        <reference ref_id="CVE-2013-1735" ref_url="http://linux.oracle.com/cve/CVE-2013-1735.html" source="CVE"/>
        <reference ref_id="CVE-2013-1736" ref_url="http://linux.oracle.com/cve/CVE-2013-1736.html" source="CVE"/>
        <reference ref_id="CVE-2013-1737" ref_url="http://linux.oracle.com/cve/CVE-2013-1737.html" source="CVE"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:10.643-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:50.724-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:27.134-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24179 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:51.803-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:19.080-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:112337"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:112120"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:112032"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:112254"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:112294"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:111812"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24175" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0449: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0449-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0449.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1518" ref_url="http://linux.oracle.com/cve/CVE-2014-1518.html" source="CVE"/>
        <reference ref_id="CVE-2014-1523" ref_url="http://linux.oracle.com/cve/CVE-2014-1523.html" source="CVE"/>
        <reference ref_id="CVE-2014-1524" ref_url="http://linux.oracle.com/cve/CVE-2014-1524.html" source="CVE"/>
        <reference ref_id="CVE-2014-1529" ref_url="http://linux.oracle.com/cve/CVE-2014-1529.html" source="CVE"/>
        <reference ref_id="CVE-2014-1530" ref_url="http://linux.oracle.com/cve/CVE-2014-1530.html" source="CVE"/>
        <reference ref_id="CVE-2014-1531" ref_url="http://linux.oracle.com/cve/CVE-2014-1531.html" source="CVE"/>
        <reference ref_id="CVE-2014-1532" ref_url="http://linux.oracle.com/cve/CVE-2014-1532.html" source="CVE"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)
A use-after-free flaw was found in the way Thunderbird resolved hosts in
certain circumstances. An attacker could use this flaw to crash Thunderbird
or, potentially, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2014-1532)
An out-of-bounds read flaw was found in the way Thunderbird decoded JPEG
images. Loading an email or a web page containing a specially crafted JPEG
image could cause Thunderbird to crash. (CVE-2014-1523)
A flaw was found in the way Thunderbird handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith and Jesse
Schwartzentrube as the original reporters of these issues.
Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.5.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:36.010-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:30.114-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:02.992-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24175 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:15.450-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:01:49.627-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:01:49.627-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113715"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114077"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24172" version="141" class="patch">
      <metadata>
        <title>ELSA-2014:0030: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2014:0030-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0030.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5870" ref_url="http://linux.oracle.com/cve/CVE-2013-5870.html" source="CVE"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5887" ref_url="http://linux.oracle.com/cve/CVE-2013-5887.html" source="CVE"/>
        <reference ref_id="CVE-2013-5888" ref_url="http://linux.oracle.com/cve/CVE-2013-5888.html" source="CVE"/>
        <reference ref_id="CVE-2013-5889" ref_url="http://linux.oracle.com/cve/CVE-2013-5889.html" source="CVE"/>
        <reference ref_id="CVE-2013-5893" ref_url="http://linux.oracle.com/cve/CVE-2013-5893.html" source="CVE"/>
        <reference ref_id="CVE-2013-5895" ref_url="http://linux.oracle.com/cve/CVE-2013-5895.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5898" ref_url="http://linux.oracle.com/cve/CVE-2013-5898.html" source="CVE"/>
        <reference ref_id="CVE-2013-5899" ref_url="http://linux.oracle.com/cve/CVE-2013-5899.html" source="CVE"/>
        <reference ref_id="CVE-2013-5902" ref_url="http://linux.oracle.com/cve/CVE-2013-5902.html" source="CVE"/>
        <reference ref_id="CVE-2013-5904" ref_url="http://linux.oracle.com/cve/CVE-2013-5904.html" source="CVE"/>
        <reference ref_id="CVE-2013-5905" ref_url="http://linux.oracle.com/cve/CVE-2013-5905.html" source="CVE"/>
        <reference ref_id="CVE-2013-5906" ref_url="http://linux.oracle.com/cve/CVE-2013-5906.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0375" ref_url="http://linux.oracle.com/cve/CVE-2014-0375.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0382" ref_url="http://linux.oracle.com/cve/CVE-2014-0382.html" source="CVE"/>
        <reference ref_id="CVE-2014-0387" ref_url="http://linux.oracle.com/cve/CVE-2014-0387.html" source="CVE"/>
        <reference ref_id="CVE-2014-0403" ref_url="http://linux.oracle.com/cve/CVE-2014-0403.html" source="CVE"/>
        <reference ref_id="CVE-2014-0410" ref_url="http://linux.oracle.com/cve/CVE-2014-0410.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0415" ref_url="http://linux.oracle.com/cve/CVE-2014-0415.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0417" ref_url="http://linux.oracle.com/cve/CVE-2014-0417.html" source="CVE"/>
        <reference ref_id="CVE-2014-0418" ref_url="http://linux.oracle.com/cve/CVE-2014-0418.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0424" ref_url="http://linux.oracle.com/cve/CVE-2014-0424.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:39.642-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:49.825-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:25.623-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24172 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:52.806-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:18.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112754"/>
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112343"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:111886"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112197"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112813"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112762"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24167" version="57" class="patch">
      <metadata>
        <title>ELSA-2014:0139: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2014:0139-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0139.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6152" ref_url="http://linux.oracle.com/cve/CVE-2012-6152.html" source="CVE"/>
        <reference ref_id="CVE-2013-6477" ref_url="http://linux.oracle.com/cve/CVE-2013-6477.html" source="CVE"/>
        <reference ref_id="CVE-2013-6478" ref_url="http://linux.oracle.com/cve/CVE-2013-6478.html" source="CVE"/>
        <reference ref_id="CVE-2013-6479" ref_url="http://linux.oracle.com/cve/CVE-2013-6479.html" source="CVE"/>
        <reference ref_id="CVE-2013-6481" ref_url="http://linux.oracle.com/cve/CVE-2013-6481.html" source="CVE"/>
        <reference ref_id="CVE-2013-6482" ref_url="http://linux.oracle.com/cve/CVE-2013-6482.html" source="CVE"/>
        <reference ref_id="CVE-2013-6483" ref_url="http://linux.oracle.com/cve/CVE-2013-6483.html" source="CVE"/>
        <reference ref_id="CVE-2013-6484" ref_url="http://linux.oracle.com/cve/CVE-2013-6484.html" source="CVE"/>
        <reference ref_id="CVE-2013-6485" ref_url="http://linux.oracle.com/cve/CVE-2013-6485.html" source="CVE"/>
        <reference ref_id="CVE-2013-6487" ref_url="http://linux.oracle.com/cve/CVE-2013-6487.html" source="CVE"/>
        <reference ref_id="CVE-2013-6489" ref_url="http://linux.oracle.com/cve/CVE-2013-6489.html" source="CVE"/>
        <reference ref_id="CVE-2013-6490" ref_url="http://linux.oracle.com/cve/CVE-2013-6490.html" source="CVE"/>
        <reference ref_id="CVE-2014-0020" ref_url="http://linux.oracle.com/cve/CVE-2014-0020.html" source="CVE"/>
        <description>The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:33.965-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:49.508-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:25.035-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24167 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:52.422-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:17.855-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112723"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112604"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112554"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112410"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112543"/>
            <criterion comment="finch is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112819"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112783"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112864"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:112308"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112276"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112667"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112333"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112136"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112628"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112811"/>
            <criterion comment="finch is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112511"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112474"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112528"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:112788"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24156" version="29" class="patch">
      <metadata>
        <title>ELSA-2014:0133: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0133-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0133.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1477" ref_url="http://linux.oracle.com/cve/CVE-2014-1477.html" source="CVE"/>
        <reference ref_id="CVE-2014-1479" ref_url="http://linux.oracle.com/cve/CVE-2014-1479.html" source="CVE"/>
        <reference ref_id="CVE-2014-1481" ref_url="http://linux.oracle.com/cve/CVE-2014-1481.html" source="CVE"/>
        <reference ref_id="CVE-2014-1482" ref_url="http://linux.oracle.com/cve/CVE-2014-1482.html" source="CVE"/>
        <reference ref_id="CVE-2014-1486" ref_url="http://linux.oracle.com/cve/CVE-2014-1486.html" source="CVE"/>
        <reference ref_id="CVE-2014-1487" ref_url="http://linux.oracle.com/cve/CVE-2014-1487.html" source="CVE"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:37.606-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.982-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:24.426-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24156 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.146-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:17.586-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:112631"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:112688"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24153" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1813: php53 and php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2013:1813-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1813.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6420" ref_url="http://linux.oracle.com/cve/CVE-2013-6420.html" source="CVE"/>
        <description>The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:10.758-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.739-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:24.214-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24153 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:51.116-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:17.361-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php53-intl is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112590"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112616"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:111824"/>
            <criterion comment="php53 is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112245"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112079"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112702"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:111715"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112638"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112690"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112598"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112050"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112542"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112235"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112671"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112480"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112659"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112467"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112660"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112007"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112152"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:112687"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112648"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:111806"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112597"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112518"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112585"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112492"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112208"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112682"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112150"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112626"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112668"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112614"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112005"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112073"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112142"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112727"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112728"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112365"/>
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112675"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112775"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112268"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112541"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112374"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112636"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112352"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112361"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:112486"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24152" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:1256: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:1256-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1256.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3361" ref_url="http://linux.oracle.com/cve/CVE-2013-3361.html" source="CVE"/>
        <reference ref_id="CVE-2013-3362" ref_url="http://linux.oracle.com/cve/CVE-2013-3362.html" source="CVE"/>
        <reference ref_id="CVE-2013-3363" ref_url="http://linux.oracle.com/cve/CVE-2013-3363.html" source="CVE"/>
        <reference ref_id="CVE-2013-5324" ref_url="http://linux.oracle.com/cve/CVE-2013-5324.html" source="CVE"/>
        <description>Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK &amp; Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3362, and CVE-2013-3363.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:58.799-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.599-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:23.986-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24152 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:48.359-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:17.193-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.310-1.el6" test_ref="oval:org.mitre.oval:tst:111450"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24148" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0447: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0447-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0447.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0515" ref_url="http://linux.oracle.com/cve/CVE-2014-0515.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed in the Adobe Security Bulletin APSB14-13, listed
in the References section.
A flaw was found in the way flash-plugin displayed certain SWF content. An
attacker could use this flaw to create a specially crafted SWF file that
would cause flash-plugin to crash or, potentially, execute arbitrary code
when the victim loaded a page containing the malicious SWF content.
(CVE-2014-0515)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.356.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:45.366-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:29.732-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:02.537-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24148 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:20.421-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:10.056-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el5" test_ref="oval:org.mitre.oval:tst:113934"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el6" test_ref="oval:org.mitre.oval:tst:113615"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24143" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1518: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:1518-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1518.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5329" ref_url="http://linux.oracle.com/cve/CVE-2013-5329.html" source="CVE"/>
        <reference ref_id="CVE-2013-5330" ref_url="http://linux.oracle.com/cve/CVE-2013-5330.html" source="CVE"/>
        <description>Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK &amp; Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:07.974-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.504-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:23.854-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24143 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:47.606-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:16.984-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.327-1.el6" test_ref="oval:org.mitre.oval:tst:111874"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24142" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1426: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2013:1426-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1426.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4396" ref_url="http://linux.oracle.com/cve/CVE-2013-4396.html" source="CVE"/>
        <description>Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:03.802-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.378-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:23.711-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24142 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:48.503-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:16.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112399"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112441"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112153"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112380"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112061"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:111496"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112135"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112286"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:112398"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112388"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:111965"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112179"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112392"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112141"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112243"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112363"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:112314"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24139" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1480: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1480-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1480.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5599" ref_url="http://linux.oracle.com/cve/CVE-2013-5599.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka presentation shell) implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors involving a CANVAS element, a mozTextStyle attribute, and an onresize event.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:11.210-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.242-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:23.534-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24139 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:48.661-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:16.710-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:111654"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:112407"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24134" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0043: bind security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2014:0043-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0043.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0591" ref_url="http://linux.oracle.com/cve/CVE-2014-0591.html" source="CVE"/>
        <description>The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:38.763-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.153-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:23.419-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24134 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.791-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:16.605-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:112404"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:112595"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:112527"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:112680"/>
          <criterion comment="bind is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:112460"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:112772"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24132" version="105" class="patch">
      <metadata>
        <title>ELSA-2014:0134: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2014:0134-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0134.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5887" ref_url="http://linux.oracle.com/cve/CVE-2013-5887.html" source="CVE"/>
        <reference ref_id="CVE-2013-5888" ref_url="http://linux.oracle.com/cve/CVE-2013-5888.html" source="CVE"/>
        <reference ref_id="CVE-2013-5889" ref_url="http://linux.oracle.com/cve/CVE-2013-5889.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5898" ref_url="http://linux.oracle.com/cve/CVE-2013-5898.html" source="CVE"/>
        <reference ref_id="CVE-2013-5899" ref_url="http://linux.oracle.com/cve/CVE-2013-5899.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0375" ref_url="http://linux.oracle.com/cve/CVE-2014-0375.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0387" ref_url="http://linux.oracle.com/cve/CVE-2014-0387.html" source="CVE"/>
        <reference ref_id="CVE-2014-0403" ref_url="http://linux.oracle.com/cve/CVE-2014-0403.html" source="CVE"/>
        <reference ref_id="CVE-2014-0410" ref_url="http://linux.oracle.com/cve/CVE-2014-0410.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0415" ref_url="http://linux.oracle.com/cve/CVE-2014-0415.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0417" ref_url="http://linux.oracle.com/cve/CVE-2014-0417.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0424" ref_url="http://linux.oracle.com/cve/CVE-2014-0424.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:37.844-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:47.481-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:22.427-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24132 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:47.932-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:15.998-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112521"/>
          <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112737"/>
          <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112652"/>
          <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112316"/>
          <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112515"/>
          <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112834"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24124" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1049: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2013:1049-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1049.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4113" ref_url="http://linux.oracle.com/cve/CVE-2013-4113.html" source="CVE"/>
        <description>ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:12.433-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:47.089-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:22.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24124 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:49.096-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:15.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-embedded is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112093"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112299"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112199"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111321"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112130"/>
            <criterion comment="php is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111823"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111298"/>
            <criterion comment="php-process is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112216"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112193"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112203"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112066"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112161"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112042"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111608"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111650"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111984"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112258"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112251"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111760"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112017"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112283"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112234"/>
            <criterion comment="php-common is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112119"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111889"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112198"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:112242"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:111666"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-xml is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112038"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112160"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112320"/>
            <criterion comment="php is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111832"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111787"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112226"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111343"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112080"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112134"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112253"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111928"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112312"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111712"/>
            <criterion comment="php-common is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111879"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112006"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112309"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:111332"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112298"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:112302"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24123" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0018: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference ref_id="ELSA-2014:0018-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0018.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6462" ref_url="http://linux.oracle.com/cve/CVE-2013-6462.html" source="CVE"/>
        <description>Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:35.638-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:47.017-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:21.953-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24123 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:45.086-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:15.516-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:112770"/>
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:112797"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:112849"/>
            <criterion comment="libXfont is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:111869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24122" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0748: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2013:0748-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0748.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1416" ref_url="http://linux.oracle.com/cve/CVE-2013-1416.html" source="CVE"/>
        <description>The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:37.053-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.943-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:21.838-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24122 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:51.942-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:15.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111803"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111331"/>
          <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111664"/>
          <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111964"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111736"/>
          <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:112028"/>
          <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111497"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24121" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1409: xinetd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference ref_id="ELSA-2013:1409-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1409.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4342" ref_url="http://linux.oracle.com/cve/CVE-2013-4342.html" source="CVE"/>
        <description>xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:03.970-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.879-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:21.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24121 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.411-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:15.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="xinetd is earlier than 2:2.3.14-39.el6_4" test_ref="oval:org.mitre.oval:tst:112450"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="xinetd is earlier than 2:2.3.14-20.el5_10" test_ref="oval:org.mitre.oval:tst:112432"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24119" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1144: nss, nss-util, nss-softokn, and nspr security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-softokn</product>
          <product>nss-util</product>
        </affected>
        <reference ref_id="ELSA-2013:1144-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1144.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0791" ref_url="http://linux.oracle.com/cve/CVE-2013-0791.html" source="CVE"/>
        <reference ref_id="CVE-2013-1620" ref_url="http://linux.oracle.com/cve/CVE-2013-1620.html" source="CVE"/>
        <description>The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:04.680-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.719-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:21.564-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24119 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:53.022-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:15.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nspr is earlier than 0:4.9.5-2.el6_4" test_ref="oval:org.mitre.oval:tst:112225"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.5-2.el6_4" test_ref="oval:org.mitre.oval:tst:112332"/>
          <criterion comment="nss-softokn-freebl is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:111400"/>
          <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:111909"/>
          <criterion comment="nss-softokn-devel is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:112215"/>
          <criterion comment="nss-softokn is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:112228"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:111791"/>
          <criterion comment="nss-tools is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:111828"/>
          <criterion comment="nss-devel is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:112099"/>
          <criterion comment="nss is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:112356"/>
          <criterion comment="nss-sysinit is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:112062"/>
          <criterion comment="nss-util-devel is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:112307"/>
          <criterion comment="nss-util is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:111799"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24118" version="37" class="patch">
      <metadata>
        <title>ELSA-2013:1476: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1476-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1476.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5590" ref_url="http://linux.oracle.com/cve/CVE-2013-5590.html" source="CVE"/>
        <reference ref_id="CVE-2013-5595" ref_url="http://linux.oracle.com/cve/CVE-2013-5595.html" source="CVE"/>
        <reference ref_id="CVE-2013-5597" ref_url="http://linux.oracle.com/cve/CVE-2013-5597.html" source="CVE"/>
        <reference ref_id="CVE-2013-5599" ref_url="http://linux.oracle.com/cve/CVE-2013-5599.html" source="CVE"/>
        <reference ref_id="CVE-2013-5600" ref_url="http://linux.oracle.com/cve/CVE-2013-5600.html" source="CVE"/>
        <reference ref_id="CVE-2013-5601" ref_url="http://linux.oracle.com/cve/CVE-2013-5601.html" source="CVE"/>
        <reference ref_id="CVE-2013-5602" ref_url="http://linux.oracle.com/cve/CVE-2013-5602.html" source="CVE"/>
        <reference ref_id="CVE-2013-5604" ref_url="http://linux.oracle.com/cve/CVE-2013-5604.html" source="CVE"/>
        <description>The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via crafted documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:50:59.155-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.496-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:21.213-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24118 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:50.785-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:14.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:112207"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:112455"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:112499"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:112508"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:112465"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:112144"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24116" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0815: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2013:0815-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0815.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3499" ref_url="http://linux.oracle.com/cve/CVE-2012-3499.html" source="CVE"/>
        <reference ref_id="CVE-2012-4558" ref_url="http://linux.oracle.com/cve/CVE-2012-4558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1862" ref_url="http://linux.oracle.com/cve/CVE-2013-1862.html" source="CVE"/>
        <description>mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:42.975-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.389-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:20.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24116 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:49.752-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:14.693-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111993"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111468"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111963"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111612"/>
            <criterion comment="httpd is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:111458"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:112026"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:111973"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:111919"/>
            <criterion comment="httpd is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:111987"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24115" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0502: Core X11 clients security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-apps</product>
          <product>xorg-x11-server-utils</product>
          <product>xorg-x11-utils</product>
        </affected>
        <reference ref_id="ELSA-2013:0502-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0502.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2504" ref_url="http://linux.oracle.com/cve/CVE-2011-2504.html" source="CVE"/>
        <description>Untrusted search path vulnerability in x11perfcomp in XFree86 x11perf before 1.5.4 allows local users to gain privileges via unspecified Trojan horse code in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:21.987-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.327-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:20.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24115 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:47.208-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:14.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xorg-x11-utils is earlier than 0:7.5-6.el6" test_ref="oval:org.mitre.oval:tst:110816"/>
          <criterion comment="xorg-x11-server-utils is earlier than 0:7.5-13.el6" test_ref="oval:org.mitre.oval:tst:110974"/>
          <criterion comment="xorg-x11-apps is earlier than 0:7.6-6.el6" test_ref="oval:org.mitre.oval:tst:111415"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24114" version="12" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0211: postgresql84 and postgresql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2014:0211-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0211.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0060" ref_url="http://linux.oracle.com/cve/CVE-2014-0060.html" source="CVE"/>
        <reference ref_id="CVE-2014-0061" ref_url="http://linux.oracle.com/cve/CVE-2014-0061.html" source="CVE"/>
        <reference ref_id="CVE-2014-0062" ref_url="http://linux.oracle.com/cve/CVE-2014-0062.html" source="CVE"/>
        <reference ref_id="CVE-2014-0063" ref_url="http://linux.oracle.com/cve/CVE-2014-0063.html" source="CVE"/>
        <reference ref_id="CVE-2014-0064" ref_url="http://linux.oracle.com/cve/CVE-2014-0064.html" source="CVE"/>
        <reference ref_id="CVE-2014-0065" ref_url="http://linux.oracle.com/cve/CVE-2014-0065.html" source="CVE"/>
        <reference ref_id="CVE-2014-0066" ref_url="http://linux.oracle.com/cve/CVE-2014-0066.html" source="CVE"/>
        <description>The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:44.038-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:20.467-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:11.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24114 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:22.802-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T18:01:15.194-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T18:01:15.194-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113123"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113254"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113358"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113516"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112870"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113563"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112971"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113181"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113427"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113343"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113564"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:113106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113541"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112895"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113331"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113425"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113534"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113479"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112901"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113349"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113420"/>
            <criterion comment="postgresql is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:113522"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24113" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0503: 389-ds-base security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference ref_id="ELSA-2013:0503-03" ref_url="http://linux.oracle.com/errata/ELSA-2013-0503.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4450" ref_url="http://linux.oracle.com/cve/CVE-2012-4450.html" source="CVE"/>
        <description>389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:31.828-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.265-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:20.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24113 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:44.502-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:14.480-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-11.el6" test_ref="oval:org.mitre.oval:tst:111451"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-11.el6" test_ref="oval:org.mitre.oval:tst:111488"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-11.el6" test_ref="oval:org.mitre.oval:tst:111131"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24109" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1473: spice-server security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>spice-server</product>
        </affected>
        <reference ref_id="ELSA-2013:1473-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1473.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4282" ref_url="http://linux.oracle.com/cve/CVE-2013-4282.html" source="CVE"/>
        <description>Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:14.389-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.203-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:20.273-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24109 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:51.444-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:14.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="spice-server is earlier than 0:0.12.0-12.el6_4.5" test_ref="oval:org.mitre.oval:tst:112497"/>
          <criterion comment="spice-server-devel is earlier than 0:0.12.0-12.el6_4.5" test_ref="oval:org.mitre.oval:tst:112289"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24108" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0528: ipa security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ipa</product>
        </affected>
        <reference ref_id="ELSA-2013:0528-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0528.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4546" ref_url="http://linux.oracle.com/cve/CVE-2012-4546.html" source="CVE"/>
        <description>The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly update another Identity Management replica, which causes inconsistent Certificate Revocation Lists (CRLs) to be used and might allow remote attackers to bypass intended access restrictions via a revoked certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:47.527-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:46.120-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:20.161-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24108 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.921-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:14.290-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ipa-server-trust-ad is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:111006"/>
          <criterion comment="ipa-python is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:111377"/>
          <criterion comment="ipa-admintools is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:111700"/>
          <criterion comment="ipa-client is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:111698"/>
          <criterion comment="ipa-server-selinux is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:111637"/>
          <criterion comment="ipa-server is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:111165"/>
          <criterion comment="ipa is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:111494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24099" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0127: librsvg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>librsvg2</product>
        </affected>
        <reference ref_id="ELSA-2014:0127-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0127.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1881" ref_url="http://linux.oracle.com/cve/CVE-2013-1881.html" source="CVE"/>
        <description>GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:42.134-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:45.837-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:19.634-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24099 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:48.785-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:14.104-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="librsvg2-devel is earlier than 0:2.26.0-6.el6_5.3" test_ref="oval:org.mitre.oval:tst:112524"/>
          <criterion comment="librsvg2 is earlier than 0:2.26.0-6.el6_5.3" test_ref="oval:org.mitre.oval:tst:112859"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24098" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0911: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0911-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0911.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1935" ref_url="http://linux.oracle.com/cve/CVE-2013-1935.html" source="CVE"/>
        <reference ref_id="CVE-2013-1943" ref_url="http://linux.oracle.com/cve/CVE-2013-1943.html" source="CVE"/>
        <reference ref_id="CVE-2013-2017" ref_url="http://linux.oracle.com/cve/CVE-2013-2017.html" source="CVE"/>
        <reference ref_id="CVE-2013-2188" ref_url="http://linux.oracle.com/cve/CVE-2013-2188.html" source="CVE"/>
        <description>A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which allows local users to cause a denial of service (system crash) by leveraging access to a filesystem that is mounted read-only.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:02.943-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:45.704-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:19.385-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24098 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:48.172-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:13.847-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:111807"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:112174"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:112122"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:111866"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:112165"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:111798"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:112214"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:111685"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:112188"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:112037"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:111892"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:111238"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24096" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1119: 389-ds-base security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference ref_id="ELSA-2013:1119-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1119.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2219" ref_url="http://linux.oracle.com/cve/CVE-2013-2219.html" source="CVE"/>
        <description>The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:07.292-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:45.641-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:19.282-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24096 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:50.919-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:13.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-20.el6_4" test_ref="oval:org.mitre.oval:tst:112280"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-20.el6_4" test_ref="oval:org.mitre.oval:tst:112085"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-20.el6_4" test_ref="oval:org.mitre.oval:tst:112178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24095" version="145" class="patch">
      <metadata>
        <title>ELSA-2013:1059: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:1059-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1059.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2437" ref_url="http://linux.oracle.com/cve/CVE-2013-2437.html" source="CVE"/>
        <reference ref_id="CVE-2013-2442" ref_url="http://linux.oracle.com/cve/CVE-2013-2442.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2451" ref_url="http://linux.oracle.com/cve/CVE-2013-2451.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2464" ref_url="http://linux.oracle.com/cve/CVE-2013-2464.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2466" ref_url="http://linux.oracle.com/cve/CVE-2013-2466.html" source="CVE"/>
        <reference ref_id="CVE-2013-2468" ref_url="http://linux.oracle.com/cve/CVE-2013-2468.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <reference ref_id="CVE-2013-3009" ref_url="http://linux.oracle.com/cve/CVE-2013-3009.html" source="CVE"/>
        <reference ref_id="CVE-2013-3011" ref_url="http://linux.oracle.com/cve/CVE-2013-3011.html" source="CVE"/>
        <reference ref_id="CVE-2013-3012" ref_url="http://linux.oracle.com/cve/CVE-2013-3012.html" source="CVE"/>
        <reference ref_id="CVE-2013-3743" ref_url="http://linux.oracle.com/cve/CVE-2013-3743.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:01.073-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:45.009-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:17.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24095 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:53.961-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:12.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111347"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112284"/>
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112315"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112159"/>
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112195"/>
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111956"/>
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112247"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24092" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0515: openchange security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>evolution-mapi</product>
          <product>openchange</product>
        </affected>
        <reference ref_id="ELSA-2013:0515-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0515.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1182" ref_url="http://linux.oracle.com/cve/CVE-2012-1182.html" source="CVE"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:34.651-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.936-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:17.754-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24092 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:44.669-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:12.833-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openchange is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:111339"/>
          <criterion comment="openchange-devel is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:111575"/>
          <criterion comment="openchange-client is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:111564"/>
          <criterion comment="openchange-devel-docs is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:111547"/>
          <criterion comment="evolution-mapi is earlier than 0:0.28.3-12.el6" test_ref="oval:org.mitre.oval:tst:111659"/>
          <criterion comment="evolution-mapi-devel is earlier than 0:0.28.3-12.el6" test_ref="oval:org.mitre.oval:tst:111582"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24091" version="29" class="patch">
      <metadata>
        <title>ELSA-2013:1142: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1142-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-1142.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1701" ref_url="http://linux.oracle.com/cve/CVE-2013-1701.html" source="CVE"/>
        <reference ref_id="CVE-2013-1709" ref_url="http://linux.oracle.com/cve/CVE-2013-1709.html" source="CVE"/>
        <reference ref_id="CVE-2013-1710" ref_url="http://linux.oracle.com/cve/CVE-2013-1710.html" source="CVE"/>
        <reference ref_id="CVE-2013-1713" ref_url="http://linux.oracle.com/cve/CVE-2013-1713.html" source="CVE"/>
        <reference ref_id="CVE-2013-1714" ref_url="http://linux.oracle.com/cve/CVE-2013-1714.html" source="CVE"/>
        <reference ref_id="CVE-2013-1717" ref_url="http://linux.oracle.com/cve/CVE-2013-1717.html" source="CVE"/>
        <description>Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:59.502-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.788-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:17.459-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24091 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:45.905-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:12.611-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el6_4" test_ref="oval:org.mitre.oval:tst:111373"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el5_9" test_ref="oval:org.mitre.oval:tst:112341"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24088" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1868: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2013:1868-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1868.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6424" ref_url="http://linux.oracle.com/cve/CVE-2013-6424.html" source="CVE"/>
        <description>Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:09.857-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.685-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:17.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24088 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:45.655-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:12.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112278"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112564"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112670"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112420"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112582"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:111858"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112739"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:112730"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112750"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112545"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112704"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112785"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112072"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112562"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112822"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112461"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:112839"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24087" version="13" class="patch">
      <metadata>
        <title>ELSA-2014:0028: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0028-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0028.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0491" ref_url="http://linux.oracle.com/cve/CVE-2014-0491.html" source="CVE"/>
        <reference ref_id="CVE-2014-0492" ref_url="http://linux.oracle.com/cve/CVE-2014-0492.html" source="CVE"/>
        <description>Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK &amp; Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:35.398-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.602-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:17.176-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24087 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:47.346-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:12.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.335-1.el6" test_ref="oval:org.mitre.oval:tst:112776"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24086" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0514: php security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2013:0514-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0514.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1398" ref_url="http://linux.oracle.com/cve/CVE-2011-1398.html" source="CVE"/>
        <reference ref_id="CVE-2012-0831" ref_url="http://linux.oracle.com/cve/CVE-2012-0831.html" source="CVE"/>
        <reference ref_id="CVE-2012-2688" ref_url="http://linux.oracle.com/cve/CVE-2012-2688.html" source="CVE"/>
        <description>Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:39.932-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.460-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:16.947-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24086 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:53.227-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:12.198-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php-pdo is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111640"/>
          <criterion comment="php-common is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111661"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:110756"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111632"/>
          <criterion comment="php-snmp is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111440"/>
          <criterion comment="php-enchant is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111384"/>
          <criterion comment="php-embedded is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111365"/>
          <criterion comment="php-devel is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111417"/>
          <criterion comment="php-recode is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:110880"/>
          <criterion comment="php is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111643"/>
          <criterion comment="php-odbc is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:110695"/>
          <criterion comment="php-gd is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111588"/>
          <criterion comment="php-imap is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111232"/>
          <criterion comment="php-tidy is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111047"/>
          <criterion comment="php-fpm is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111491"/>
          <criterion comment="php-soap is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111430"/>
          <criterion comment="php-mysql is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111405"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111524"/>
          <criterion comment="php-process is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111068"/>
          <criterion comment="php-intl is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111501"/>
          <criterion comment="php-zts is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111531"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111178"/>
          <criterion comment="php-ldap is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111609"/>
          <criterion comment="php-cli is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:110948"/>
          <criterion comment="php-dba is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111133"/>
          <criterion comment="php-xml is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111633"/>
          <criterion comment="php-pspell is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:111141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24085" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0277: dnsmasq security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dnsmasq</product>
        </affected>
        <reference ref_id="ELSA-2013:0277-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0277.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3411" ref_url="http://linux.oracle.com/cve/CVE-2012-3411.html" source="CVE"/>
        <description>Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:24.974-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.397-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:16.843-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24085 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:48.903-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="dnsmasq-utils is earlier than 0:2.48-13.el6" test_ref="oval:org.mitre.oval:tst:111233"/>
          <criterion comment="dnsmasq is earlier than 0:2.48-13.el6" test_ref="oval:org.mitre.oval:tst:110658"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24083" version="29" class="patch">
      <metadata>
        <title>ELSA-2013:1140: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1140-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1140.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1701" ref_url="http://linux.oracle.com/cve/CVE-2013-1701.html" source="CVE"/>
        <reference ref_id="CVE-2013-1709" ref_url="http://linux.oracle.com/cve/CVE-2013-1709.html" source="CVE"/>
        <reference ref_id="CVE-2013-1710" ref_url="http://linux.oracle.com/cve/CVE-2013-1710.html" source="CVE"/>
        <reference ref_id="CVE-2013-1713" ref_url="http://linux.oracle.com/cve/CVE-2013-1713.html" source="CVE"/>
        <reference ref_id="CVE-2013-1714" ref_url="http://linux.oracle.com/cve/CVE-2013-1714.html" source="CVE"/>
        <reference ref_id="CVE-2013-1717" ref_url="http://linux.oracle.com/cve/CVE-2013-1717.html" source="CVE"/>
        <description>Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:09.410-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.166-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:16.424-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24083 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:46.276-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:17.0.8-1.el6_4" test_ref="oval:org.mitre.oval:tst:111950"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el6_4" test_ref="oval:org.mitre.oval:tst:111913"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el6_4" test_ref="oval:org.mitre.oval:tst:112109"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:17.0.8-1.el5_9" test_ref="oval:org.mitre.oval:tst:112304"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el5_9" test_ref="oval:org.mitre.oval:tst:112338"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el5_9" test_ref="oval:org.mitre.oval:tst:112012"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24082" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1101: virtio-win security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>virtio-win</product>
        </affected>
        <reference ref_id="ELSA-2013:1101-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1101.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2231" ref_url="http://linux.oracle.com/cve/CVE-2013-2231.html" source="CVE"/>
        <description>Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, and Workstation Supplementary 6, when installing on Windows, allows local users to gain privileges via a crafted program in an unspecified folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:06.396-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:44.071-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:16.323-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24082 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:49.891-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="virtio-win is earlier than 0:1.6.5-6.el6_4" test_ref="oval:org.mitre.oval:tst:112250"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24076" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0609: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2013:0609-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0609.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6075" ref_url="http://linux.oracle.com/cve/CVE-2012-6075.html" source="CVE"/>
        <description>Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:47.741-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:43.860-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:16.055-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24076 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:50.003-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-guest-agent-win32 is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:111601"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:111701"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:111696"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:111634"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:111796"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24075" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:1850: openjpeg security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openjpeg</product>
        </affected>
        <reference ref_id="ELSA-2013:1850-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1850.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1447" ref_url="http://linux.oracle.com/cve/CVE-2013-1447.html" source="CVE"/>
        <reference ref_id="CVE-2013-6045" ref_url="http://linux.oracle.com/cve/CVE-2013-6045.html" source="CVE"/>
        <reference ref_id="CVE-2013-6052" ref_url="http://linux.oracle.com/cve/CVE-2013-6052.html" source="CVE"/>
        <reference ref_id="CVE-2013-6054" ref_url="http://linux.oracle.com/cve/CVE-2013-6054.html" source="CVE"/>
        <description>Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:11.366-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:43.740-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:15.844-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24075 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:49.340-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.363-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openjpeg is earlier than 0:1.3-10.el6_5" test_ref="oval:org.mitre.oval:tst:112617"/>
          <criterion comment="openjpeg-libs is earlier than 0:1.3-10.el6_5" test_ref="oval:org.mitre.oval:tst:112519"/>
          <criterion comment="openjpeg-devel is earlier than 0:1.3-10.el6_5" test_ref="oval:org.mitre.oval:tst:112377"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24072" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0600: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2013:0600-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0600.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0809" ref_url="http://linux.oracle.com/cve/CVE-2013-0809.html" source="CVE"/>
        <reference ref_id="CVE-2013-1493" ref_url="http://linux.oracle.com/cve/CVE-2013-1493.html" source="CVE"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:46.668-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:43.682-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:15.773-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24072 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:51.330-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111397"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111386"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111755"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111268"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111596"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111419"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24071" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0941: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:0941-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0941.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3343" ref_url="http://linux.oracle.com/cve/CVE-2013-3343.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.90 and 11.x before 11.7.700.224 on Windows, before 10.3.183.90 and 11.x before 11.7.700.225 on Mac OS X, before 10.3.183.90 and 11.x before 11.2.202.291 on Linux, before 11.1.111.59 on Android 2.x and 3.x, and before 11.1.115.63 on Android 4.x; Adobe AIR before 3.7.0.2090 on Windows and Android and before 3.7.0.2100 on Mac OS X; and Adobe AIR SDK &amp; Compiler before 3.7.0.2090 on Windows and before 3.7.0.2100 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:11.604-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:43.617-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:15.679-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24071 - optimisation of Oracle Linux content" date="2014-05-05T17:17:00.672-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:19:44.962-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.291-1.el6" test_ref="oval:org.mitre.oval:tst:112187"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24070" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0605: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0605-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0605.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0809" ref_url="http://linux.oracle.com/cve/CVE-2013-0809.html" source="CVE"/>
        <reference ref_id="CVE-2013-1493" ref_url="http://linux.oracle.com/cve/CVE-2013-1493.html" source="CVE"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:43.951-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:43.529-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:15.535-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24070 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:20.998-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:07.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:111749"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:111820"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:111797"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:111421"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:111585"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24069" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0646: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2013:0646-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0646.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0272" ref_url="http://linux.oracle.com/cve/CVE-2013-0272.html" source="CVE"/>
        <reference ref_id="CVE-2013-0273" ref_url="http://linux.oracle.com/cve/CVE-2013-0273.html" source="CVE"/>
        <reference ref_id="CVE-2013-0274" ref_url="http://linux.oracle.com/cve/CVE-2013-0274.html" source="CVE"/>
        <description>upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:34.956-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:43.394-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:15.250-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24069 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:07.121-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:11.002-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111551"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111094"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111483"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111846"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111055"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111837"/>
            <criterion comment="finch is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111814"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111293"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111505"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111594"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111805"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111667"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111758"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111794"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111605"/>
            <criterion comment="finch is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111535"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111227"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111752"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:111769"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24063" version="93" class="patch">
      <metadata>
        <title>ELSA-2013:0247: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0247-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0247.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0424" ref_url="http://linux.oracle.com/cve/CVE-2013-0424.html" source="CVE"/>
        <reference ref_id="CVE-2013-0425" ref_url="http://linux.oracle.com/cve/CVE-2013-0425.html" source="CVE"/>
        <reference ref_id="CVE-2013-0426" ref_url="http://linux.oracle.com/cve/CVE-2013-0426.html" source="CVE"/>
        <reference ref_id="CVE-2013-0427" ref_url="http://linux.oracle.com/cve/CVE-2013-0427.html" source="CVE"/>
        <reference ref_id="CVE-2013-0428" ref_url="http://linux.oracle.com/cve/CVE-2013-0428.html" source="CVE"/>
        <reference ref_id="CVE-2013-0429" ref_url="http://linux.oracle.com/cve/CVE-2013-0429.html" source="CVE"/>
        <reference ref_id="CVE-2013-0431" ref_url="http://linux.oracle.com/cve/CVE-2013-0431.html" source="CVE"/>
        <reference ref_id="CVE-2013-0432" ref_url="http://linux.oracle.com/cve/CVE-2013-0432.html" source="CVE"/>
        <reference ref_id="CVE-2013-0433" ref_url="http://linux.oracle.com/cve/CVE-2013-0433.html" source="CVE"/>
        <reference ref_id="CVE-2013-0434" ref_url="http://linux.oracle.com/cve/CVE-2013-0434.html" source="CVE"/>
        <reference ref_id="CVE-2013-0435" ref_url="http://linux.oracle.com/cve/CVE-2013-0435.html" source="CVE"/>
        <reference ref_id="CVE-2013-0440" ref_url="http://linux.oracle.com/cve/CVE-2013-0440.html" source="CVE"/>
        <reference ref_id="CVE-2013-0441" ref_url="http://linux.oracle.com/cve/CVE-2013-0441.html" source="CVE"/>
        <reference ref_id="CVE-2013-0442" ref_url="http://linux.oracle.com/cve/CVE-2013-0442.html" source="CVE"/>
        <reference ref_id="CVE-2013-0443" ref_url="http://linux.oracle.com/cve/CVE-2013-0443.html" source="CVE"/>
        <reference ref_id="CVE-2013-0444" ref_url="http://linux.oracle.com/cve/CVE-2013-0444.html" source="CVE"/>
        <reference ref_id="CVE-2013-0445" ref_url="http://linux.oracle.com/cve/CVE-2013-0445.html" source="CVE"/>
        <reference ref_id="CVE-2013-0450" ref_url="http://linux.oracle.com/cve/CVE-2013-0450.html" source="CVE"/>
        <reference ref_id="CVE-2013-1475" ref_url="http://linux.oracle.com/cve/CVE-2013-1475.html" source="CVE"/>
        <reference ref_id="CVE-2013-1476" ref_url="http://linux.oracle.com/cve/CVE-2013-1476.html" source="CVE"/>
        <reference ref_id="CVE-2013-1478" ref_url="http://linux.oracle.com/cve/CVE-2013-1478.html" source="CVE"/>
        <reference ref_id="CVE-2013-1480" ref_url="http://linux.oracle.com/cve/CVE-2013-1480.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.	 NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:29.312-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:42.863-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:14.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24063 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:21:58.114-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:10.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:110864"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:111489"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:111500"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:110519"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:110987"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111372"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111425"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111089"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111015"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:111288"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24061" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0272: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0272-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0272.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0775" ref_url="http://linux.oracle.com/cve/CVE-2013-0775.html" source="CVE"/>
        <reference ref_id="CVE-2013-0776" ref_url="http://linux.oracle.com/cve/CVE-2013-0776.html" source="CVE"/>
        <reference ref_id="CVE-2013-0780" ref_url="http://linux.oracle.com/cve/CVE-2013-0780.html" source="CVE"/>
        <reference ref_id="CVE-2013-0782" ref_url="http://linux.oracle.com/cve/CVE-2013-0782.html" source="CVE"/>
        <reference ref_id="CVE-2013-0783" ref_url="http://linux.oracle.com/cve/CVE-2013-0783.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:28.157-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:42.647-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:13.871-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24061 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:01.137-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:10.220-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:110654"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:111310"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24058" version="5" class="patch">
      <metadata>
        <title>ELSA-2013:0666: Oracle Java SE 6 - notification of end of public updates (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2013:0666-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0666.html" source="VENDOR"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
Oracle Java SE 6 will not receive updates after February 28, 2013. The
Oracle Java SE 6 packages on the Oracle Linux 5.x and 6
Supplementary media and in Red Hat Network (RHN) channels will continue to
be available.
Red Hat will continue to provide these packages only as a courtesy to
customers. Red Hat will not provide updates to these packages after this
date.
Once customers update their system by installing the packages associated
with this advisory, the Oracle Java Web Plug-in will be disabled. As a
result, customers who rely on Java-based browser applets may need to
re-configure their browser to use one of the Java implementations listed
in the Solution section below.
All users of java-1.6.0-sun are advised to upgrade to these updated
packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:51.691-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:42.593-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:13.775-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24058 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:00.824-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:09.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:111834"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:111671"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:111718"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:111819"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:111224"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:111767"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24055" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0630: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0630-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0630.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0228" ref_url="http://linux.oracle.com/cve/CVE-2013-0228.html" source="CVE"/>
        <reference ref_id="CVE-2013-0268" ref_url="http://linux.oracle.com/cve/CVE-2013-0268.html" source="CVE"/>
        <description>The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:43.630-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:42.329-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:13.347-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24055 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.179-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:09.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111502"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111852"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111772"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111809"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111776"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111071"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111838"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111699"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111789"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111333"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111287"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:111250"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24053" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0687: pixman security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference ref_id="ELSA-2013:0687-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0687.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1591" ref_url="http://linux.oracle.com/cve/CVE-2013-1591.html" source="CVE"/>
        <description>Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors.  NOTE: this issue might be resultant from an integer overflow in the fast_composite_scaled_bilinear function in pixman-inlines.h, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:55.396-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:42.195-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:13.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24053 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:04.197-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:09.754-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pixman-devel is earlier than 0:0.26.2-5.el6_4" test_ref="oval:org.mitre.oval:tst:111860"/>
          <criterion comment="pixman is earlier than 0:0.26.2-5.el6_4" test_ref="oval:org.mitre.oval:tst:111692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24052" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0689: bind security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2013:0689-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0689.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2266" ref_url="http://linux.oracle.com/cve/CVE-2013-2266.html" source="CVE"/>
        <description>libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:43.388-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:42.124-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:13.024-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24052 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.334-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:09.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:111937"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:111249"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:111957"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:111903"/>
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:111674"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:111318"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24051" version="85" class="patch">
      <metadata>
        <title>ELSA-2013:0770: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0770-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0770.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-1488" ref_url="http://linux.oracle.com/cve/CVE-2013-1488.html" source="CVE"/>
        <reference ref_id="CVE-2013-1518" ref_url="http://linux.oracle.com/cve/CVE-2013-1518.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1558" ref_url="http://linux.oracle.com/cve/CVE-2013-1558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2415" ref_url="http://linux.oracle.com/cve/CVE-2013-2415.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2421" ref_url="http://linux.oracle.com/cve/CVE-2013-2421.html" source="CVE"/>
        <reference ref_id="CVE-2013-2422" ref_url="http://linux.oracle.com/cve/CVE-2013-2422.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2426" ref_url="http://linux.oracle.com/cve/CVE-2013-2426.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2431" ref_url="http://linux.oracle.com/cve/CVE-2013-2431.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to bypassing the Java sandbox using "method handle intrinsic frames."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:34.114-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:41.704-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:12.163-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24051 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:06.222-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:09.129-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:112023"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:111348"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:111917"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:111717"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:111985"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:111777"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:111922"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:111988"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:112031"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:111953"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24050" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1475: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2013:1475-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1475.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0255" ref_url="http://linux.oracle.com/cve/CVE-2013-0255.html" source="CVE"/>
        <reference ref_id="CVE-2013-1000" ref_url="http://linux.oracle.com/cve/CVE-2013-1000.html" source="CVE"/>
        <description>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:00.891-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:41.540-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:11.980-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24050 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.512-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:08.967-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql-devel is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112509"/>
            <criterion comment="postgresql is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112297"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112446"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112496"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:111878"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112428"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112162"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112139"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112366"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:112505"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112348"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112503"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112500"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112313"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:111939"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112279"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112421"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112448"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112359"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112425"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112510"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:112364"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24047" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0663: sssd security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sssd</product>
        </affected>
        <reference ref_id="ELSA-2013:0663-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0663.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0287" ref_url="http://linux.oracle.com/cve/CVE-2013-0287.html" source="CVE"/>
        <description>The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:45.515-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:41.291-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:11.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24047 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:21:58.532-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:08.854-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="sssd-client is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111670"/>
          <criterion comment="libipa_hbac-python is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111655"/>
          <criterion comment="libsss_sudo is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111808"/>
          <criterion comment="sssd is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111784"/>
          <criterion comment="libipa_hbac is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111766"/>
          <criterion comment="libsss_idmap is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111720"/>
          <criterion comment="libsss_autofs is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111574"/>
          <criterion comment="libipa_hbac-devel is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111854"/>
          <criterion comment="sssd-tools is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111646"/>
          <criterion comment="libsss_idmap-devel is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111802"/>
          <criterion comment="libsss_sudo-devel is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:111849"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24046" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0246: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2014:0246-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0246.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0096" ref_url="http://linux.oracle.com/cve/CVE-2014-0096.html" source="CVE"/>
        <description>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).
It was discovered that GnuTLS did not correctly handle certain errors that
could occur during the verification of an X.509 certificate, causing it to
incorrectly report a successful verification. An attacker could use this
flaw to create a specially crafted certificate that could be accepted by
GnuTLS as valid for a site chosen by the attacker. (CVE-2014-0092)
The CVE-2014-0092 issue was discovered by Nikos Mavrogiannopoulos of the
Red Hat Security Technologies Team.
Users of GnuTLS are advised to upgrade to these updated packages, which
correct this issue. For the update to take effect, all applications linked
to the GnuTLS library must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:32.711-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:28.266-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:02.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24046 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:19.114-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:07.205-04:00">ACCEPTED</status_change>
            <modified comment="duplicate of oval:org.mitre.oval:def:24508" date="2014-07-23T14:43:11.306-04:00">
              <contributor organization="Hewlett-Packard">Manu MG</contributor>
            </modified>
            <status_change date="2014-07-23T14:43:11.306-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gnutls-guile is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:114023"/>
          <criterion comment="gnutls-utils is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:114026"/>
          <criterion comment="gnutls-devel is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:114269"/>
          <criterion comment="gnutls is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:114207"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24045" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0964: tomcat6 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference ref_id="ELSA-2013:0964-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0964.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2067" ref_url="http://linux.oracle.com/cve/CVE-2013-2067.html" source="CVE"/>
        <description>java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:10.415-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:41.205-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:11.438-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24045 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:06.070-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:08.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:112236"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:112137"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:112056"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:112196"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:112252"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:112009"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:112140"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:112022"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:112131"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24043" version="105" class="patch">
      <metadata>
        <title>ELSA-2013:1014: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:1014-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1014.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.	NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:12.976-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:40.651-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:10.327-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24043 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:04.758-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:08.473-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:112116"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:112147"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:112248"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:111991"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:112049"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:111836"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:112123"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:112266"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:112263"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:112211"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24042" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0448: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0448-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0448.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1518" ref_url="http://linux.oracle.com/cve/CVE-2014-1518.html" source="CVE"/>
        <reference ref_id="CVE-2014-1523" ref_url="http://linux.oracle.com/cve/CVE-2014-1523.html" source="CVE"/>
        <reference ref_id="CVE-2014-1524" ref_url="http://linux.oracle.com/cve/CVE-2014-1524.html" source="CVE"/>
        <reference ref_id="CVE-2014-1529" ref_url="http://linux.oracle.com/cve/CVE-2014-1529.html" source="CVE"/>
        <reference ref_id="CVE-2014-1530" ref_url="http://linux.oracle.com/cve/CVE-2014-1530.html" source="CVE"/>
        <reference ref_id="CVE-2014-1531" ref_url="http://linux.oracle.com/cve/CVE-2014-1531.html" source="CVE"/>
        <reference ref_id="CVE-2014-1532" ref_url="http://linux.oracle.com/cve/CVE-2014-1532.html" source="CVE"/>
        <description>Mozilla Firefox is an open source web browser.
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)
A use-after-free flaw was found in the way Firefox resolved hosts in
certain circumstances. An attacker could use this flaw to crash Firefox or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1532)
An out-of-bounds read flaw was found in the way Firefox decoded JPEG
images. Loading a web page containing a specially crafted JPEG image could
cause Firefox to crash. (CVE-2014-1523)
A flaw was found in the way Firefox handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)
Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith, and Jesse
Schwartzentrube as the original reporters of these issues.
For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.5.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.
All Firefox users should upgrade to this updated package, which contains
Firefox version 24.5.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:38.968-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:27.594-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:01.461-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24042 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:30.510-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:59:29.932-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:59:29.932-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:114191"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114123"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24038" version="73" class="patch">
      <metadata>
        <title>ELSA-2013:0254: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:0254-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0254.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0637" ref_url="http://linux.oracle.com/cve/CVE-2013-0637.html" source="CVE"/>
        <reference ref_id="CVE-2013-0638" ref_url="http://linux.oracle.com/cve/CVE-2013-0638.html" source="CVE"/>
        <reference ref_id="CVE-2013-0639" ref_url="http://linux.oracle.com/cve/CVE-2013-0639.html" source="CVE"/>
        <reference ref_id="CVE-2013-0642" ref_url="http://linux.oracle.com/cve/CVE-2013-0642.html" source="CVE"/>
        <reference ref_id="CVE-2013-0644" ref_url="http://linux.oracle.com/cve/CVE-2013-0644.html" source="CVE"/>
        <reference ref_id="CVE-2013-0645" ref_url="http://linux.oracle.com/cve/CVE-2013-0645.html" source="CVE"/>
        <reference ref_id="CVE-2013-0647" ref_url="http://linux.oracle.com/cve/CVE-2013-0647.html" source="CVE"/>
        <reference ref_id="CVE-2013-0649" ref_url="http://linux.oracle.com/cve/CVE-2013-0649.html" source="CVE"/>
        <reference ref_id="CVE-2013-1365" ref_url="http://linux.oracle.com/cve/CVE-2013-1365.html" source="CVE"/>
        <reference ref_id="CVE-2013-1366" ref_url="http://linux.oracle.com/cve/CVE-2013-1366.html" source="CVE"/>
        <reference ref_id="CVE-2013-1367" ref_url="http://linux.oracle.com/cve/CVE-2013-1367.html" source="CVE"/>
        <reference ref_id="CVE-2013-1368" ref_url="http://linux.oracle.com/cve/CVE-2013-1368.html" source="CVE"/>
        <reference ref_id="CVE-2013-1369" ref_url="http://linux.oracle.com/cve/CVE-2013-1369.html" source="CVE"/>
        <reference ref_id="CVE-2013-1370" ref_url="http://linux.oracle.com/cve/CVE-2013-1370.html" source="CVE"/>
        <reference ref_id="CVE-2013-1372" ref_url="http://linux.oracle.com/cve/CVE-2013-1372.html" source="CVE"/>
        <reference ref_id="CVE-2013-1373" ref_url="http://linux.oracle.com/cve/CVE-2013-1373.html" source="CVE"/>
        <reference ref_id="CVE-2013-1374" ref_url="http://linux.oracle.com/cve/CVE-2013-1374.html" source="CVE"/>
        <description>Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0644 and CVE-2013-0649.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:25.120-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:40.231-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:09.483-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24038 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:06.799-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:08.054-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.270-1.el6" test_ref="oval:org.mitre.oval:tst:110968"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24037" version="105" class="patch">
      <metadata>
        <title>ELSA-2014:0135: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2014:0135-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0135.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5887" ref_url="http://linux.oracle.com/cve/CVE-2013-5887.html" source="CVE"/>
        <reference ref_id="CVE-2013-5888" ref_url="http://linux.oracle.com/cve/CVE-2013-5888.html" source="CVE"/>
        <reference ref_id="CVE-2013-5889" ref_url="http://linux.oracle.com/cve/CVE-2013-5889.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5898" ref_url="http://linux.oracle.com/cve/CVE-2013-5898.html" source="CVE"/>
        <reference ref_id="CVE-2013-5899" ref_url="http://linux.oracle.com/cve/CVE-2013-5899.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0375" ref_url="http://linux.oracle.com/cve/CVE-2014-0375.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0387" ref_url="http://linux.oracle.com/cve/CVE-2014-0387.html" source="CVE"/>
        <reference ref_id="CVE-2014-0403" ref_url="http://linux.oracle.com/cve/CVE-2014-0403.html" source="CVE"/>
        <reference ref_id="CVE-2014-0410" ref_url="http://linux.oracle.com/cve/CVE-2014-0410.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0415" ref_url="http://linux.oracle.com/cve/CVE-2014-0415.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0417" ref_url="http://linux.oracle.com/cve/CVE-2014-0417.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0424" ref_url="http://linux.oracle.com/cve/CVE-2014-0424.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:34.825-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:39.732-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:08.462-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24037 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:00.048-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:07.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112807"/>
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112275"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112683"/>
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112858"/>
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112736"/>
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112644"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:112765"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24036" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1803: libjpeg-turbo security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libjpeg-turbo</product>
        </affected>
        <reference ref_id="ELSA-2013:1803-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1803.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6630" ref_url="http://linux.oracle.com/cve/CVE-2013-6630.html" source="CVE"/>
        <description>The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:07.208-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:39.652-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:08.329-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24036 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:08.060-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:07.332-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libjpeg-turbo is earlier than 0:1.2.1-3.el6_5" test_ref="oval:org.mitre.oval:tst:112387"/>
          <criterion comment="libjpeg-turbo-static is earlier than 0:1.2.1-3.el6_5" test_ref="oval:org.mitre.oval:tst:112645"/>
          <criterion comment="libjpeg-turbo-devel is earlier than 0:1.2.1-3.el6_5" test_ref="oval:org.mitre.oval:tst:112323"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24032" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0511: pki-core security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pki-core</product>
        </affected>
        <reference ref_id="ELSA-2013:0511-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0511.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4543" ref_url="http://linux.oracle.com/cve/CVE-2012-4543.html" source="CVE"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:42.551-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:39.561-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:08.214-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24032 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.678-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:07.127-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pki-ca is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111327"/>
          <criterion comment="pki-selinux is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111529"/>
          <criterion comment="pki-common is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111538"/>
          <criterion comment="pki-java-tools-javadoc is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111453"/>
          <criterion comment="pki-util is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111364"/>
          <criterion comment="pki-setup is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111534"/>
          <criterion comment="pki-core is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111346"/>
          <criterion comment="pki-util-javadoc is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111295"/>
          <criterion comment="pki-silent is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111665"/>
          <criterion comment="pki-native-tools is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111175"/>
          <criterion comment="pki-java-tools is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111475"/>
          <criterion comment="pki-common-javadoc is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111560"/>
          <criterion comment="pki-symkey is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:111555"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24031" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0623: tomcat6 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference ref_id="ELSA-2013:0623-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0623.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3546" ref_url="http://linux.oracle.com/cve/CVE-2012-3546.html" source="CVE"/>
        <reference ref_id="CVE-2012-4534" ref_url="http://linux.oracle.com/cve/CVE-2012-4534.html" source="CVE"/>
        <reference ref_id="CVE-2012-5885" ref_url="http://linux.oracle.com/cve/CVE-2012-5885.html" source="CVE"/>
        <reference ref_id="CVE-2012-5886" ref_url="http://linux.oracle.com/cve/CVE-2012-5886.html" source="CVE"/>
        <reference ref_id="CVE-2012-5887" ref_url="http://linux.oracle.com/cve/CVE-2012-5887.html" source="CVE"/>
        <description>The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:45.720-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:39.414-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:07.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24031 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:07.874-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:06.930-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:111412"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:111620"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:111597"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:111759"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:111150"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:111826"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:111827"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:111493"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:111625"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24028" version="113" class="patch">
      <metadata>
        <title>ELSA-2013:1081: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:1081-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1081.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2464" ref_url="http://linux.oracle.com/cve/CVE-2013-2464.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <reference ref_id="CVE-2013-3009" ref_url="http://linux.oracle.com/cve/CVE-2013-3009.html" source="CVE"/>
        <reference ref_id="CVE-2013-3011" ref_url="http://linux.oracle.com/cve/CVE-2013-3011.html" source="CVE"/>
        <reference ref_id="CVE-2013-3012" ref_url="http://linux.oracle.com/cve/CVE-2013-3012.html" source="CVE"/>
        <reference ref_id="CVE-2013-3743" ref_url="http://linux.oracle.com/cve/CVE-2013-3743.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:58.083-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:38.819-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:06.823-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24028 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:21:59.250-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:06.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112084"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112101"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112121"/>
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112190"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112295"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112183"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111638"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24025" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0526: automake security update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>automake</product>
        </affected>
        <reference ref_id="ELSA-2013:0526-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0526.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3386" ref_url="http://linux.oracle.com/cve/CVE-2012-3386.html" source="CVE"/>
        <description>The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:41.641-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:38.762-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:06.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24025 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:00.944-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:06.205-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="automake is earlier than 0:1.11.1-4.el6" test_ref="oval:org.mitre.oval:tst:111645"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24024" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0508: sssd security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sssd</product>
        </affected>
        <reference ref_id="ELSA-2013:0508-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0508.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0219" ref_url="http://linux.oracle.com/cve/CVE-2013-0219.html" source="CVE"/>
        <reference ref_id="CVE-2013-0220" ref_url="http://linux.oracle.com/cve/CVE-2013-0220.html" source="CVE"/>
        <description>The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:31.477-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:38.667-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:06.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24024 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:02.060-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:06.069-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="sssd-client is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111533"/>
          <criterion comment="libipa_hbac-python is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111342"/>
          <criterion comment="libsss_sudo is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111337"/>
          <criterion comment="sssd is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:110604"/>
          <criterion comment="libipa_hbac is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111570"/>
          <criterion comment="libsss_idmap is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111562"/>
          <criterion comment="libsss_autofs is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111323"/>
          <criterion comment="libipa_hbac-devel is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111297"/>
          <criterion comment="sssd-tools is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111470"/>
          <criterion comment="libsss_idmap-devel is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111486"/>
          <criterion comment="libsss_sudo-devel is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:111429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24021" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0884: libtirpc security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtirpc</product>
        </affected>
        <reference ref_id="ELSA-2013:0884-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0884.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1950" ref_url="http://linux.oracle.com/cve/CVE-2013-1950.html" source="CVE"/>
        <description>The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:58.669-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:38.602-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:06.424-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24021 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:01.744-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:05.965-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libtirpc-devel is earlier than 0:0.2.1-6.el6_4" test_ref="oval:org.mitre.oval:tst:112115"/>
          <criterion comment="libtirpc is earlier than 0:0.2.1-6.el6_4" test_ref="oval:org.mitre.oval:tst:111162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24020" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0521: pam security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pam</product>
        </affected>
        <reference ref_id="ELSA-2013:0521-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0521.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3148" ref_url="http://linux.oracle.com/cve/CVE-2011-3148.html" source="CVE"/>
        <reference ref_id="CVE-2011-3149" ref_url="http://linux.oracle.com/cve/CVE-2011-3149.html" source="CVE"/>
        <description>The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:34.113-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:38.523-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:06.290-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24020 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:04.450-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:05.845-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pam-devel is earlier than 0:1.1.1-13.el6" test_ref="oval:org.mitre.oval:tst:110724"/>
          <criterion comment="pam is earlier than 0:1.1.1-13.el6" test_ref="oval:org.mitre.oval:tst:111509"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24019" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1764: ruby security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2013:1764-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1764.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4164" ref_url="http://linux.oracle.com/cve/CVE-2013-4164.html" source="CVE"/>
        <description>Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a string that is converted to a floating point value, as demonstrated using (1) the to_f method or (2) JSON.parse.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:11.083-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:38.450-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:06.169-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24019 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:06.392-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:05.670-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:112476"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:112362"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:112259"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:111530"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:112145"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:112102"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:112163"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:112452"/>
          <criterion comment="ruby is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:112167"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24015" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0574: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:0574-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0574.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0504" ref_url="http://linux.oracle.com/cve/CVE-2013-0504.html" source="CVE"/>
        <reference ref_id="CVE-2013-0643" ref_url="http://linux.oracle.com/cve/CVE-2013-0643.html" source="CVE"/>
        <reference ref_id="CVE-2013-0648" ref_url="http://linux.oracle.com/cve/CVE-2013-0648.html" source="CVE"/>
        <description>Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:37.313-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:38.355-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:05.991-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24015 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:00.606-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:05.363-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.273-1.el6" test_ref="oval:org.mitre.oval:tst:111432"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24014" version="45" class="patch">
      <metadata>
        <title>ELSA-2013:0820: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0820-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0820.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0801" ref_url="http://linux.oracle.com/cve/CVE-2013-0801.html" source="CVE"/>
        <reference ref_id="CVE-2013-1670" ref_url="http://linux.oracle.com/cve/CVE-2013-1670.html" source="CVE"/>
        <reference ref_id="CVE-2013-1674" ref_url="http://linux.oracle.com/cve/CVE-2013-1674.html" source="CVE"/>
        <reference ref_id="CVE-2013-1675" ref_url="http://linux.oracle.com/cve/CVE-2013-1675.html" source="CVE"/>
        <reference ref_id="CVE-2013-1676" ref_url="http://linux.oracle.com/cve/CVE-2013-1676.html" source="CVE"/>
        <reference ref_id="CVE-2013-1677" ref_url="http://linux.oracle.com/cve/CVE-2013-1677.html" source="CVE"/>
        <reference ref_id="CVE-2013-1678" ref_url="http://linux.oracle.com/cve/CVE-2013-1678.html" source="CVE"/>
        <reference ref_id="CVE-2013-1679" ref_url="http://linux.oracle.com/cve/CVE-2013-1679.html" source="CVE"/>
        <reference ref_id="CVE-2013-1680" ref_url="http://linux.oracle.com/cve/CVE-2013-1680.html" source="CVE"/>
        <reference ref_id="CVE-2013-1681" ref_url="http://linux.oracle.com/cve/CVE-2013-1681.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:47.684-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:38.127-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:05.563-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24014 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:01.435-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:05.020-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:17.0.6-1.el6_4" test_ref="oval:org.mitre.oval:tst:111992"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:111842"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:111931"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:111861"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:111921"/>
            <criterion comment="firefox is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:111902"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24011" version="161" class="patch">
      <metadata>
        <title>ELSA-2013:1508: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:1508-04" ref_url="http://linux.oracle.com/errata/ELSA-2013-1508.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4041" ref_url="http://linux.oracle.com/cve/CVE-2013-4041.html" source="CVE"/>
        <reference ref_id="CVE-2013-5372" ref_url="http://linux.oracle.com/cve/CVE-2013-5372.html" source="CVE"/>
        <reference ref_id="CVE-2013-5375" ref_url="http://linux.oracle.com/cve/CVE-2013-5375.html" source="CVE"/>
        <reference ref_id="CVE-2013-5457" ref_url="http://linux.oracle.com/cve/CVE-2013-5457.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5776" ref_url="http://linux.oracle.com/cve/CVE-2013-5776.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5787" ref_url="http://linux.oracle.com/cve/CVE-2013-5787.html" source="CVE"/>
        <reference ref_id="CVE-2013-5789" ref_url="http://linux.oracle.com/cve/CVE-2013-5789.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5801" ref_url="http://linux.oracle.com/cve/CVE-2013-5801.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5812" ref_url="http://linux.oracle.com/cve/CVE-2013-5812.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5818" ref_url="http://linux.oracle.com/cve/CVE-2013-5818.html" source="CVE"/>
        <reference ref_id="CVE-2013-5819" ref_url="http://linux.oracle.com/cve/CVE-2013-5819.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5824" ref_url="http://linux.oracle.com/cve/CVE-2013-5824.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5831" ref_url="http://linux.oracle.com/cve/CVE-2013-5831.html" source="CVE"/>
        <reference ref_id="CVE-2013-5832" ref_url="http://linux.oracle.com/cve/CVE-2013-5832.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5843" ref_url="http://linux.oracle.com/cve/CVE-2013-5843.html" source="CVE"/>
        <reference ref_id="CVE-2013-5848" ref_url="http://linux.oracle.com/cve/CVE-2013-5848.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <reference ref_id="CVE-2013-5851" ref_url="http://linux.oracle.com/cve/CVE-2013-5851.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:05.502-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:37.374-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:04.085-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24011 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:07.391-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:04.028-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112459"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112318"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112036"/>
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112218"/>
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111727"/>
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112426"/>
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24010" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0830: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0830-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0830.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2094" ref_url="http://linux.oracle.com/cve/CVE-2013-2094.html" source="CVE"/>
        <description>The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:37.812-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:37.283-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:03.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24010 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:08.186-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:03.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:112047"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:111816"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:111436"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:111688"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:111115"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:111606"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:111908"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:112069"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:112078"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:111996"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:111069"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:111929"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24007" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1182: 389-ds-base security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference ref_id="ELSA-2013:1182-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1182.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4283" ref_url="http://linux.oracle.com/cve/CVE-2013-4283.html" source="CVE"/>
        <description>ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:02.250-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:37.180-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:03.853-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24007 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:06.940-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:03.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-22.el6_4" test_ref="oval:org.mitre.oval:tst:111704"/>
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-22.el6_4" test_ref="oval:org.mitre.oval:tst:112060"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-22.el6_4" test_ref="oval:org.mitre.oval:tst:112273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24006" version="93" class="patch">
      <metadata>
        <title>ELSA-2013:0751: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0751-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0751.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-1488" ref_url="http://linux.oracle.com/cve/CVE-2013-1488.html" source="CVE"/>
        <reference ref_id="CVE-2013-1518" ref_url="http://linux.oracle.com/cve/CVE-2013-1518.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1558" ref_url="http://linux.oracle.com/cve/CVE-2013-1558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2415" ref_url="http://linux.oracle.com/cve/CVE-2013-2415.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2421" ref_url="http://linux.oracle.com/cve/CVE-2013-2421.html" source="CVE"/>
        <reference ref_id="CVE-2013-2422" ref_url="http://linux.oracle.com/cve/CVE-2013-2422.html" source="CVE"/>
        <reference ref_id="CVE-2013-2423" ref_url="http://linux.oracle.com/cve/CVE-2013-2423.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2426" ref_url="http://linux.oracle.com/cve/CVE-2013-2426.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2431" ref_url="http://linux.oracle.com/cve/CVE-2013-2431.html" source="CVE"/>
        <reference ref_id="CVE-2013-2436" ref_url="http://linux.oracle.com/cve/CVE-2013-2436.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-1488 and CVE-2013-2426.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "type checks" and "method handle binding" involving Wrapper.convert.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:52.734-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:36.764-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:02.855-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24006 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:08.519-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:03.154-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:111947"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:111557"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:111829"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:112025"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:111911"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24005" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1457: libgcrypt security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libgcrypt</product>
        </affected>
        <reference ref_id="ELSA-2013:1457-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1457.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4242" ref_url="http://linux.oracle.com/cve/CVE-2013-4242.html" source="CVE"/>
        <description>GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:09.491-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:36.695-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:02.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24005 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:08.339-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:03.054-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:112453"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:112513"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:112393"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:112369"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24000" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1805: samba4 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference ref_id="ELSA-2013:1805-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1805.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4408" ref_url="http://linux.oracle.com/cve/CVE-2013-4408.html" source="CVE"/>
        <description>Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:12.582-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:36.506-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:02.519-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24000 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:21:59.451-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:02.818-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112621"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112589"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112296"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112570"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112260"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:111732"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112559"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112666"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112634"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112125"/>
          <criterion comment="samba4 is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112663"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112502"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112532"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112711"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23998" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0250: elinks security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>elinks</product>
        </affected>
        <reference ref_id="ELSA-2013:0250-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0250.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4545" ref_url="http://linux.oracle.com/cve/CVE-2012-4545.html" source="CVE"/>
        <description>The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:28.530-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:36.337-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:02.398-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23998 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.808-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:02.617-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="elinks is earlier than 0:0.12-0.21.pre5.el6_3" test_ref="oval:org.mitre.oval:tst:111438"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="elinks is earlier than 0:0.11.1-8.el5_9" test_ref="oval:org.mitre.oval:tst:111328"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23997" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0525: pcsc-lite security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pcsc-lite</product>
        </affected>
        <reference ref_id="ELSA-2013:0525-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0525.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4531" ref_url="http://linux.oracle.com/cve/CVE-2010-4531.html" source="CVE"/>
        <description>Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrhandler.c) for pcscd in PCSC-Lite 1.5.3, and possibly other 1.5.x and 1.6.x versions, allows physically proximate attackers to cause a denial of service (crash) and possibly execute arbitrary code via a smart card with an ATR message containing a long attribute value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:37.771-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:36.228-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:02.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23997 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:04.313-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:02.494-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pcsc-lite-libs is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:111652"/>
          <criterion comment="pcsc-lite-devel is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:110989"/>
          <criterion comment="pcsc-lite is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:111595"/>
          <criterion comment="pcsc-lite-doc is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:111578"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23995" version="33" class="patch">
      <metadata>
        <title>ELSA-2012:1431: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:1431-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1431.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5274" ref_url="http://linux.oracle.com/cve/CVE-2012-5274.html" source="CVE"/>
        <reference ref_id="CVE-2012-5275" ref_url="http://linux.oracle.com/cve/CVE-2012-5275.html" source="CVE"/>
        <reference ref_id="CVE-2012-5276" ref_url="http://linux.oracle.com/cve/CVE-2012-5276.html" source="CVE"/>
        <reference ref_id="CVE-2012-5277" ref_url="http://linux.oracle.com/cve/CVE-2012-5277.html" source="CVE"/>
        <reference ref_id="CVE-2012-5278" ref_url="http://linux.oracle.com/cve/CVE-2012-5278.html" source="CVE"/>
        <reference ref_id="CVE-2012-5279" ref_url="http://linux.oracle.com/cve/CVE-2012-5279.html" source="CVE"/>
        <reference ref_id="CVE-2012-5280" ref_url="http://linux.oracle.com/cve/CVE-2012-5280.html" source="CVE"/>
        <description>Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, and CVE-2012-5277.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:08.928-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.929-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:01.830-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23995 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:04.072-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:02.263-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.251-1.el6" test_ref="oval:org.mitre.oval:tst:111280"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23994" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0447: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2014:0447-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0447.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0515" ref_url="http://linux.oracle.com/cve/CVE-2014-0515.html" source="CVE"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.
This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed in the Adobe Security Bulletin APSB14-13, listed
in the References section.
A flaw was found in the way flash-plugin displayed certain SWF content. An
attacker could use this flaw to create a specially crafted SWF file that
would cause flash-plugin to crash or, potentially, execute arbitrary code
when the victim loaded a page containing the malicious SWF content.
(CVE-2014-0515)
All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.356.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:30.556-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:27.055-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:00.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23994 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:21.145-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:58:55.950-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:58:55.950-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el5" test_ref="oval:org.mitre.oval:tst:114242"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el6" test_ref="oval:org.mitre.oval:tst:113355"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23993" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0505: squid security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference ref_id="ELSA-2013:0505-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0505.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5643" ref_url="http://linux.oracle.com/cve/CVE-2012-5643.html" source="CVE"/>
        <description>Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:21.816-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.859-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:01.728-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23993 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:00.202-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:02.167-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="squid is earlier than 7:3.1.10-16.el6" test_ref="oval:org.mitre.oval:tst:111308"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23991" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1139: bind-dyndb-ldap security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind-dyndb-ldap</product>
        </affected>
        <reference ref_id="ELSA-2012:1139-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1139.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3429" ref_url="http://linux.oracle.com/cve/CVE-2012-3429.html" source="CVE"/>
        <description>The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a "$" character in a DN in a DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:52.310-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.798-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:01.627-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23991 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:00.304-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:02.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="bind-dyndb-ldap is earlier than 0:1.1.0-0.9.b1.el6_3.1" test_ref="oval:org.mitre.oval:tst:110820"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23989" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1284: spice-gtk security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>spice-gtk</product>
        </affected>
        <reference ref_id="ELSA-2012:1284-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1284.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4425" ref_url="http://linux.oracle.com/cve/CVE-2012-4425.html" source="CVE"/>
        <description>libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable.	NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:10.150-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.642-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:01.390-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23989 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:02.193-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:01.921-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="spice-gtk-tools is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:111066"/>
          <criterion comment="spice-glib-devel is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:111174"/>
          <criterion comment="spice-glib is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:111193"/>
          <criterion comment="spice-gtk-python is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:110596"/>
          <criterion comment="spice-gtk is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:110973"/>
          <criterion comment="spice-gtk-devel is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:111204"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23987" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1090: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2013:1090-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1090.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4073" ref_url="http://linux.oracle.com/cve/CVE-2013-4073.html" source="CVE"/>
        <description>The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:59.134-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.538-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:01.235-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23987 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:01.883-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:01.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112277"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112081"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112014"/>
            <criterion comment="ruby-static is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112238"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112063"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112339"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112204"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:112301"/>
            <criterion comment="ruby is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:111946"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112265"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112317"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112321"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:111682"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:111898"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112008"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112166"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112075"/>
            <criterion comment="ruby is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:112281"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23985" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0408: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0408-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0408.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.
An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)
Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)
Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)
Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)
Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)
It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)
It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)
It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)
An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)
This update also fixes the following bug:
* The OpenJDK update to IcedTea version 1.13 introduced a regression
related to the handling of the jdk_version_info variable. This variable was
not properly zeroed out before being passed to the Java Virtual Machine,
resulting in a memory leak in the java.lang.ref.Finalizer class.
This update fixes this issue, and memory leaks no longer occur.
(BZ#1085373)
All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:36.715-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:25.405-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:59.842-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23985 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:28.620-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:05.730-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113857"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114138"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114246"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113249"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113792"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114001"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113931"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113677"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114214"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113692"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23981" version="21" class="patch">
      <metadata>
        <title>ELSA-2014:0159: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2014:0159-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0159.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2929" ref_url="http://linux.oracle.com/cve/CVE-2013-2929.html" source="CVE"/>
        <reference ref_id="CVE-2013-6381" ref_url="http://linux.oracle.com/cve/CVE-2013-6381.html" source="CVE"/>
        <reference ref_id="CVE-2013-7263" ref_url="http://linux.oracle.com/cve/CVE-2013-7263.html" source="CVE"/>
        <reference ref_id="CVE-2013-7265" ref_url="http://linux.oracle.com/cve/CVE-2013-7265.html" source="CVE"/>
        <description>The pn_recvmsg function in net/phonet/datagram.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:36.477-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.317-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:00.641-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23981 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.010-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:01.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112773"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112619"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112835"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112522"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:111901"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112561"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112718"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112745"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112689"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112669"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112555"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112876"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:112769"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23980" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0880: qt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference ref_id="ELSA-2012:0880-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0880.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-5076" ref_url="http://linux.oracle.com/cve/CVE-2010-5076.html" source="CVE"/>
        <reference ref_id="CVE-2011-3922" ref_url="http://linux.oracle.com/cve/CVE-2011-3922.html" source="CVE"/>
        <description>Stack-based buffer overflow in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to glyph handling.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:32.704-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.211-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:00.472-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23980 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:21:57.549-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:01.099-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qt-odbc is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:110432"/>
          <criterion comment="qt-demos is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:109881"/>
          <criterion comment="qt-mysql is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:110437"/>
          <criterion comment="qt-x11 is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:110038"/>
          <criterion comment="qt-doc is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:110477"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:109639"/>
          <criterion comment="qt-sqlite is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:110566"/>
          <criterion comment="qt-postgresql is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:110335"/>
          <criterion comment="qt is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:109694"/>
          <criterion comment="qt-examples is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:110637"/>
          <criterion comment="qt-devel is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:110347"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23978" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0696: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0696-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0696.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0788" ref_url="http://linux.oracle.com/cve/CVE-2013-0788.html" source="CVE"/>
        <reference ref_id="CVE-2013-0793" ref_url="http://linux.oracle.com/cve/CVE-2013-0793.html" source="CVE"/>
        <reference ref_id="CVE-2013-0795" ref_url="http://linux.oracle.com/cve/CVE-2013-0795.html" source="CVE"/>
        <reference ref_id="CVE-2013-0796" ref_url="http://linux.oracle.com/cve/CVE-2013-0796.html" source="CVE"/>
        <reference ref_id="CVE-2013-0800" ref_url="http://linux.oracle.com/cve/CVE-2013-0800.html" source="CVE"/>
        <description>Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:51.997-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:35.063-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:00.221-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23978 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:21:58.375-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:00.786-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111949"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111603"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111739"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111739"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111737"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111662"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111695"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111695"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23976" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0580: cups security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference ref_id="ELSA-2013:0580-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0580.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5519" ref_url="http://linux.oracle.com/cve/CVE-2012-5519.html" source="CVE"/>
        <description>CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:36.483-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:34.974-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:00.094-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23976 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:05.934-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:00.635-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cups-php is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111747"/>
            <criterion comment="cups-lpd is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111619"/>
            <criterion comment="cups-devel is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111697"/>
            <criterion comment="cups is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111708"/>
            <criterion comment="cups-libs is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:111480"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cups-devel is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:111540"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:111668"/>
            <criterion comment="cups is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:111614"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:111702"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23975" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0601: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2013:0601-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0601.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0809" ref_url="http://linux.oracle.com/cve/CVE-2013-0809.html" source="CVE"/>
        <reference ref_id="CVE-2013-1493" ref_url="http://linux.oracle.com/cve/CVE-2013-1493.html" source="CVE"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:48.476-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:34.885-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:59.953-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23975 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:00.448-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:00.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111627"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111517"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111565"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111452"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111733"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111435"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23974" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1270: polkit security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>polkit</product>
        </affected>
        <reference ref_id="ELSA-2013:1270-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1270.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4288" ref_url="http://linux.oracle.com/cve/CVE-2013-4288.html" source="CVE"/>
        <description>Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:05.617-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:34.815-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:59.847-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23974 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:21:58.665-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:00.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="polkit-desktop-policy is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:112376"/>
          <criterion comment="polkit-devel is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:112169"/>
          <criterion comment="polkit is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:112438"/>
          <criterion comment="polkit-docs is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:112095"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23972" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0668: boost security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>boost</product>
        </affected>
        <reference ref_id="ELSA-2013:0668-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0668.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2677" ref_url="http://linux.oracle.com/cve/CVE-2012-2677.html" source="CVE"/>
        <description>Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:40.421-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:34.663-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:59.685-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23972 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:07.632-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:00.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="boost-graph-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111706"/>
            <criterion comment="boost-graph-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111868"/>
            <criterion comment="boost-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111389"/>
            <criterion comment="boost-test is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111409"/>
            <criterion comment="boost-graph is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111847"/>
            <criterion comment="boost is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111610"/>
            <criterion comment="boost-mpich2-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111833"/>
            <criterion comment="boost-wave is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111783"/>
            <criterion comment="boost-filesystem is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111881"/>
            <criterion comment="boost-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111693"/>
            <criterion comment="boost-thread is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111394"/>
            <criterion comment="boost-mpich2-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111841"/>
            <criterion comment="boost-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111647"/>
            <criterion comment="boost-static is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111294"/>
            <criterion comment="boost-doc is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111813"/>
            <criterion comment="boost-regex is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111374"/>
            <criterion comment="boost-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111642"/>
            <criterion comment="boost-openmpi-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:110890"/>
            <criterion comment="boost-serialization is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111738"/>
            <criterion comment="boost-system is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111817"/>
            <criterion comment="boost-iostreams is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111864"/>
            <criterion comment="boost-signals is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:110896"/>
            <criterion comment="boost-program-options is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111000"/>
            <criterion comment="boost-openmpi-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111883"/>
            <criterion comment="boost-date-time is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111743"/>
            <criterion comment="boost-math is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:111572"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="boost is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:111877"/>
            <criterion comment="boost-doc is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:111822"/>
            <criterion comment="boost-devel is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:111792"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23971" version="101" class="patch">
      <metadata>
        <title>ELSA-2012:1210: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1210-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1210.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1970" ref_url="http://linux.oracle.com/cve/CVE-2012-1970.html" source="CVE"/>
        <reference ref_id="CVE-2012-1972" ref_url="http://linux.oracle.com/cve/CVE-2012-1972.html" source="CVE"/>
        <reference ref_id="CVE-2012-1973" ref_url="http://linux.oracle.com/cve/CVE-2012-1973.html" source="CVE"/>
        <reference ref_id="CVE-2012-1974" ref_url="http://linux.oracle.com/cve/CVE-2012-1974.html" source="CVE"/>
        <reference ref_id="CVE-2012-1975" ref_url="http://linux.oracle.com/cve/CVE-2012-1975.html" source="CVE"/>
        <reference ref_id="CVE-2012-1976" ref_url="http://linux.oracle.com/cve/CVE-2012-1976.html" source="CVE"/>
        <reference ref_id="CVE-2012-3956" ref_url="http://linux.oracle.com/cve/CVE-2012-3956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3957" ref_url="http://linux.oracle.com/cve/CVE-2012-3957.html" source="CVE"/>
        <reference ref_id="CVE-2012-3958" ref_url="http://linux.oracle.com/cve/CVE-2012-3958.html" source="CVE"/>
        <reference ref_id="CVE-2012-3959" ref_url="http://linux.oracle.com/cve/CVE-2012-3959.html" source="CVE"/>
        <reference ref_id="CVE-2012-3960" ref_url="http://linux.oracle.com/cve/CVE-2012-3960.html" source="CVE"/>
        <reference ref_id="CVE-2012-3961" ref_url="http://linux.oracle.com/cve/CVE-2012-3961.html" source="CVE"/>
        <reference ref_id="CVE-2012-3962" ref_url="http://linux.oracle.com/cve/CVE-2012-3962.html" source="CVE"/>
        <reference ref_id="CVE-2012-3963" ref_url="http://linux.oracle.com/cve/CVE-2012-3963.html" source="CVE"/>
        <reference ref_id="CVE-2012-3964" ref_url="http://linux.oracle.com/cve/CVE-2012-3964.html" source="CVE"/>
        <reference ref_id="CVE-2012-3966" ref_url="http://linux.oracle.com/cve/CVE-2012-3966.html" source="CVE"/>
        <reference ref_id="CVE-2012-3967" ref_url="http://linux.oracle.com/cve/CVE-2012-3967.html" source="CVE"/>
        <reference ref_id="CVE-2012-3968" ref_url="http://linux.oracle.com/cve/CVE-2012-3968.html" source="CVE"/>
        <reference ref_id="CVE-2012-3969" ref_url="http://linux.oracle.com/cve/CVE-2012-3969.html" source="CVE"/>
        <reference ref_id="CVE-2012-3970" ref_url="http://linux.oracle.com/cve/CVE-2012-3970.html" source="CVE"/>
        <reference ref_id="CVE-2012-3972" ref_url="http://linux.oracle.com/cve/CVE-2012-3972.html" source="CVE"/>
        <reference ref_id="CVE-2012-3976" ref_url="http://linux.oracle.com/cve/CVE-2012-3976.html" source="CVE"/>
        <reference ref_id="CVE-2012-3978" ref_url="http://linux.oracle.com/cve/CVE-2012-3978.html" source="CVE"/>
        <reference ref_id="CVE-2012-3980" ref_url="http://linux.oracle.com/cve/CVE-2012-3980.html" source="CVE"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:41.132-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:34.101-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:58.750-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23971 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:03.794-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:59.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:110728"/>
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:110757"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:110810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:110831"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:110952"/>
            <criterion comment="firefox is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:110856"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23970" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0869: tomcat6 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference ref_id="ELSA-2013:0869-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0869.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1976" ref_url="http://linux.oracle.com/cve/CVE-2013-1976.html" source="CVE"/>
        <reference ref_id="CVE-2013-2051" ref_url="http://linux.oracle.com/cve/CVE-2013-2051.html" source="CVE"/>
        <description>The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale.  NOTE: this issue is due to an incomplete fix for CVE-2012-5887.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:46.672-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:33.972-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:58.582-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23970 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:01.624-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:59.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:112094"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:112068"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:111795"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:111427"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:112055"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:111757"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:111938"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:111835"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:111785"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23969" version="197" class="patch">
      <metadata>
        <title>ELSA-2013:1440: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2013:1440-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-1440.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5775" ref_url="http://linux.oracle.com/cve/CVE-2013-5775.html" source="CVE"/>
        <reference ref_id="CVE-2013-5776" ref_url="http://linux.oracle.com/cve/CVE-2013-5776.html" source="CVE"/>
        <reference ref_id="CVE-2013-5777" ref_url="http://linux.oracle.com/cve/CVE-2013-5777.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5787" ref_url="http://linux.oracle.com/cve/CVE-2013-5787.html" source="CVE"/>
        <reference ref_id="CVE-2013-5788" ref_url="http://linux.oracle.com/cve/CVE-2013-5788.html" source="CVE"/>
        <reference ref_id="CVE-2013-5789" ref_url="http://linux.oracle.com/cve/CVE-2013-5789.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5800" ref_url="http://linux.oracle.com/cve/CVE-2013-5800.html" source="CVE"/>
        <reference ref_id="CVE-2013-5801" ref_url="http://linux.oracle.com/cve/CVE-2013-5801.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5810" ref_url="http://linux.oracle.com/cve/CVE-2013-5810.html" source="CVE"/>
        <reference ref_id="CVE-2013-5812" ref_url="http://linux.oracle.com/cve/CVE-2013-5812.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5818" ref_url="http://linux.oracle.com/cve/CVE-2013-5818.html" source="CVE"/>
        <reference ref_id="CVE-2013-5819" ref_url="http://linux.oracle.com/cve/CVE-2013-5819.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5824" ref_url="http://linux.oracle.com/cve/CVE-2013-5824.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5831" ref_url="http://linux.oracle.com/cve/CVE-2013-5831.html" source="CVE"/>
        <reference ref_id="CVE-2013-5832" ref_url="http://linux.oracle.com/cve/CVE-2013-5832.html" source="CVE"/>
        <reference ref_id="CVE-2013-5838" ref_url="http://linux.oracle.com/cve/CVE-2013-5838.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5843" ref_url="http://linux.oracle.com/cve/CVE-2013-5843.html" source="CVE"/>
        <reference ref_id="CVE-2013-5844" ref_url="http://linux.oracle.com/cve/CVE-2013-5844.html" source="CVE"/>
        <reference ref_id="CVE-2013-5846" ref_url="http://linux.oracle.com/cve/CVE-2013-5846.html" source="CVE"/>
        <reference ref_id="CVE-2013-5848" ref_url="http://linux.oracle.com/cve/CVE-2013-5848.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <reference ref_id="CVE-2013-5851" ref_url="http://linux.oracle.com/cve/CVE-2013-5851.html" source="CVE"/>
        <reference ref_id="CVE-2013-5852" ref_url="http://linux.oracle.com/cve/CVE-2013-5852.html" source="CVE"/>
        <reference ref_id="CVE-2013-5854" ref_url="http://linux.oracle.com/cve/CVE-2013-5854.html" source="CVE"/>
        <reference ref_id="CVE-2014-1111" ref_url="http://linux.oracle.com/cve/CVE-2014-1111.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:02.428-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:33.033-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:56.731-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23969 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:03.165-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:58.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:112391"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:112429"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:112156"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:112205"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111520"/>
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:112445"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23968" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0408: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0408-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0408.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.
An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)
Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)
Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)
Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)
Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)
It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)
It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)
It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)
An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)
This update also fixes the following bug:
* The OpenJDK update to IcedTea version 1.13 introduced a regression
related to the handling of the jdk_version_info variable. This variable was
not properly zeroed out before being passed to the Java Virtual Machine,
resulting in a memory leak in the java.lang.ref.Finalizer class.
This update fixes this issue, and memory leaks no longer occur.
(BZ#1085373)
All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:30.912-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:23.829-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:58.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23968 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:17.449-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:58:19.309-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:58:19.309-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114070"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113559"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114258"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114161"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113996"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113773"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114185"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113325"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114225"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114194"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23966" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0876: net-snmp security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>net-snmp</product>
        </affected>
        <reference ref_id="ELSA-2012:0876-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0876.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2141" ref_url="http://linux.oracle.com/cve/CVE-2012-2141.html" source="CVE"/>
        <description>Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:38.056-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.945-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:56.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23966 - optimisation of Oracle Linux content" date="2014-05-05T17:19:00.903-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:22:00.721-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:58.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="net-snmp-python is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:110231"/>
          <criterion comment="net-snmp-devel is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:109592"/>
          <criterion comment="net-snmp is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:110011"/>
          <criterion comment="net-snmp-utils is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:110520"/>
          <criterion comment="net-snmp-perl is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:110516"/>
          <criterion comment="net-snmp-libs is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:110012"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23965" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0581: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2013:0581-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0581.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0338" ref_url="http://linux.oracle.com/cve/CVE-2013-0338.html" source="CVE"/>
        <description>libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:42.022-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.868-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:56.489-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23965 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:30.946-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:57:20.879-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:57:20.879-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:111466"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:111687"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:111677"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:111615"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:111525"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:111492"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:111128"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23962" version="33" class="patch">
      <metadata>
        <title>ELSA-2012:1255: libexif security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>libexif</product>
        </affected>
        <reference ref_id="ELSA-2012:1255-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1255.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2812" ref_url="http://linux.oracle.com/cve/CVE-2012-2812.html" source="CVE"/>
        <reference ref_id="CVE-2012-2813" ref_url="http://linux.oracle.com/cve/CVE-2012-2813.html" source="CVE"/>
        <reference ref_id="CVE-2012-2814" ref_url="http://linux.oracle.com/cve/CVE-2012-2814.html" source="CVE"/>
        <reference ref_id="CVE-2012-2836" ref_url="http://linux.oracle.com/cve/CVE-2012-2836.html" source="CVE"/>
        <reference ref_id="CVE-2012-2837" ref_url="http://linux.oracle.com/cve/CVE-2012-2837.html" source="CVE"/>
        <reference ref_id="CVE-2012-2840" ref_url="http://linux.oracle.com/cve/CVE-2012-2840.html" source="CVE"/>
        <reference ref_id="CVE-2012-2841" ref_url="http://linux.oracle.com/cve/CVE-2012-2841.html" source="CVE"/>
        <description>Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:37.640-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.681-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:56.064-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23962 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.671-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:57.856-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:110958"/>
            <criterion comment="libexif is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:110938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:110821"/>
            <criterion comment="libexif is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:110400"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23961" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1779: mod_nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>mod_nss</product>
        </affected>
        <reference ref_id="ELSA-2013:1779-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1779.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4566" ref_url="http://linux.oracle.com/cve/CVE-2013-4566.html" source="CVE"/>
        <description>mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:50:58.658-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.610-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:55.962-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23961 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:43.072-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:57.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="mod_nss is earlier than 0:1.0.8-8.el5_10" test_ref="oval:org.mitre.oval:tst:112632"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="mod_nss is earlier than 0:1.0.8-19.el6_5" test_ref="oval:org.mitre.oval:tst:112370"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23960" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:1225: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2012:1225-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1225.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0547" ref_url="http://linux.oracle.com/cve/CVE-2012-0547.html" source="CVE"/>
        <reference ref_id="CVE-2012-1682" ref_url="http://linux.oracle.com/cve/CVE-2012-1682.html" source="CVE"/>
        <reference ref_id="CVE-2012-3136" ref_url="http://linux.oracle.com/cve/CVE-2012-3136.html" source="CVE"/>
        <reference ref_id="CVE-2012-4681" ref_url="http://linux.oracle.com/cve/CVE-2012-4681.html" source="CVE"/>
        <description>Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:48.502-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.495-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:55.718-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23960 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.940-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:57.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:111082"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:110967"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:110854"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:111048"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:110876"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23959" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:1413: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1413-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1413.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4194" ref_url="http://linux.oracle.com/cve/CVE-2012-4194.html" source="CVE"/>
        <reference ref_id="CVE-2012-4195" ref_url="http://linux.oracle.com/cve/CVE-2012-4195.html" source="CVE"/>
        <reference ref_id="CVE-2012-4196" ref_url="http://linux.oracle.com/cve/CVE-2012-4196.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:11.727-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.393-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:55.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23959 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.873-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:57.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:111070"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:111057"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23958" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0151: wget security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>wget</product>
        </affected>
        <reference ref_id="ELSA-2014:0151-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0151.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2252" ref_url="http://linux.oracle.com/cve/CVE-2010-2252.html" source="CVE"/>
        <description>GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:34.540-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.331-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:55.441-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23958 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.132-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:57.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="wget is earlier than 0:1.12-1.11.el6_5" test_ref="oval:org.mitre.oval:tst:112823"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23957" version="37" class="patch">
      <metadata>
        <title>ELSA-2012:1173: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:1173-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1173.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1535" ref_url="http://linux.oracle.com/cve/CVE-2012-1535.html" source="CVE"/>
        <reference ref_id="CVE-2012-4163" ref_url="http://linux.oracle.com/cve/CVE-2012-4163.html" source="CVE"/>
        <reference ref_id="CVE-2012-4164" ref_url="http://linux.oracle.com/cve/CVE-2012-4164.html" source="CVE"/>
        <reference ref_id="CVE-2012-4165" ref_url="http://linux.oracle.com/cve/CVE-2012-4165.html" source="CVE"/>
        <reference ref_id="CVE-2012-4166" ref_url="http://linux.oracle.com/cve/CVE-2012-4166.html" source="CVE"/>
        <reference ref_id="CVE-2012-4167" ref_url="http://linux.oracle.com/cve/CVE-2012-4167.html" source="CVE"/>
        <reference ref_id="CVE-2012-4168" ref_url="http://linux.oracle.com/cve/CVE-2012-4168.html" source="CVE"/>
        <reference ref_id="CVE-2012-5054" ref_url="http://linux.oracle.com/cve/CVE-2012-5054.html" source="CVE"/>
        <description>Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:39.553-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.136-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:55.067-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23957 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.139-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:57.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.238-1.el6" test_ref="oval:org.mitre.oval:tst:110481"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23956" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0499: xinetd security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference ref_id="ELSA-2013:0499-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0499.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0862" ref_url="http://linux.oracle.com/cve/CVE-2012-0862.html" source="CVE"/>
        <description>builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:19.657-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.077-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:54.970-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23956 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:37.472-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:56.963-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="xinetd is earlier than 2:2.3.14-38.el6" test_ref="oval:org.mitre.oval:tst:111561"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23955" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1234: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2012:1234-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1234.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3515" ref_url="http://linux.oracle.com/cve/CVE-2012-3515.html" source="CVE"/>
        <description>Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:55.164-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:32.013-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:54.868-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23955 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.132-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:56.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:110970"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:111052"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:110836"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:110542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23954" version="121" class="patch">
      <metadata>
        <title>ELSA-2013:1451: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:1451-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1451.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5800" ref_url="http://linux.oracle.com/cve/CVE-2013-5800.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5838" ref_url="http://linux.oracle.com/cve/CVE-2013-5838.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <reference ref_id="CVE-2013-5851" ref_url="http://linux.oracle.com/cve/CVE-2013-5851.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:04.177-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:31.861-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:54.647-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23954 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.633-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:56.649-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:112439"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:112405"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:111844"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:112378"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:112447"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23953" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:1223: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2012:1223-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1223.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0547" ref_url="http://linux.oracle.com/cve/CVE-2012-0547.html" source="CVE"/>
        <reference ref_id="CVE-2012-1682" ref_url="http://linux.oracle.com/cve/CVE-2012-1682.html" source="CVE"/>
        <reference ref_id="CVE-2012-3136" ref_url="http://linux.oracle.com/cve/CVE-2012-3136.html" source="CVE"/>
        <reference ref_id="CVE-2012-4681" ref_url="http://linux.oracle.com/cve/CVE-2012-4681.html" source="CVE"/>
        <description>Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:49.410-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:31.746-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:54.405-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23953 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.361-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:56.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110897"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110884"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110908"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110505"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110114"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23952" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1362: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1362-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1362.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4193" ref_url="http://linux.oracle.com/cve/CVE-2012-4193.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:04.034-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:31.683-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:54.306-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23952 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.769-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:56.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:111270"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:110601"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23950" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0771: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2013:0771-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0771.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1944" ref_url="http://linux.oracle.com/cve/CVE-2013-1944.html" source="CVE"/>
        <description>The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:52.421-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:31.615-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:54.196-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23950 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.829-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:56.323-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:111910"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:111775"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:111053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:111930"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:112003"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23949" version="109" class="patch">
      <metadata>
        <title>ELSA-2013:1505: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:1505-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1505.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:14.639-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:31.079-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:53.107-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23949 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.325-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:55.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:112311"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:112324"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:112408"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:112292"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:111781"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112373"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112018"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112336"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112155"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:112389"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23948" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0697: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0697-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0697.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0788" ref_url="http://linux.oracle.com/cve/CVE-2013-0788.html" source="CVE"/>
        <reference ref_id="CVE-2013-0793" ref_url="http://linux.oracle.com/cve/CVE-2013-0793.html" source="CVE"/>
        <reference ref_id="CVE-2013-0795" ref_url="http://linux.oracle.com/cve/CVE-2013-0795.html" source="CVE"/>
        <reference ref_id="CVE-2013-0796" ref_url="http://linux.oracle.com/cve/CVE-2013-0796.html" source="CVE"/>
        <reference ref_id="CVE-2013-0800" ref_url="http://linux.oracle.com/cve/CVE-2013-0800.html" source="CVE"/>
        <description>Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:41.925-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.909-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:52.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23948 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.310-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:55.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111884"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:111867"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23946" version="45" class="patch">
      <metadata>
        <title>ELSA-2013:0821: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0821-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0821.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0801" ref_url="http://linux.oracle.com/cve/CVE-2013-0801.html" source="CVE"/>
        <reference ref_id="CVE-2013-1670" ref_url="http://linux.oracle.com/cve/CVE-2013-1670.html" source="CVE"/>
        <reference ref_id="CVE-2013-1674" ref_url="http://linux.oracle.com/cve/CVE-2013-1674.html" source="CVE"/>
        <reference ref_id="CVE-2013-1675" ref_url="http://linux.oracle.com/cve/CVE-2013-1675.html" source="CVE"/>
        <reference ref_id="CVE-2013-1676" ref_url="http://linux.oracle.com/cve/CVE-2013-1676.html" source="CVE"/>
        <reference ref_id="CVE-2013-1677" ref_url="http://linux.oracle.com/cve/CVE-2013-1677.html" source="CVE"/>
        <reference ref_id="CVE-2013-1678" ref_url="http://linux.oracle.com/cve/CVE-2013-1678.html" source="CVE"/>
        <reference ref_id="CVE-2013-1679" ref_url="http://linux.oracle.com/cve/CVE-2013-1679.html" source="CVE"/>
        <reference ref_id="CVE-2013-1680" ref_url="http://linux.oracle.com/cve/CVE-2013-1680.html" source="CVE"/>
        <reference ref_id="CVE-2013-1681" ref_url="http://linux.oracle.com/cve/CVE-2013-1681.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:35.323-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.700-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:52.233-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23946 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.778-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:55.106-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:111920"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:112002"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23945" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1288: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:1288-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1288.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3102" ref_url="http://linux.oracle.com/cve/CVE-2011-3102.html" source="CVE"/>
        <reference ref_id="CVE-2012-2807" ref_url="http://linux.oracle.com/cve/CVE-2012-2807.html" source="CVE"/>
        <description>Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:12.399-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.610-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:52.084-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23945 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:36.463-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:54.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:110961"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:111143"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:111093"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:110476"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:111154"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:111027"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:110924"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23943" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0512: httpd security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2013:0512-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0512.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-0455" ref_url="http://linux.oracle.com/cve/CVE-2008-0455.html" source="CVE"/>
        <reference ref_id="CVE-2012-2687" ref_url="http://linux.oracle.com/cve/CVE-2012-2687.html" source="CVE"/>
        <reference ref_id="CVE-2012-4557" ref_url="http://linux.oracle.com/cve/CVE-2012-4557.html" source="CVE"/>
        <description>The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:45.114-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.506-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:51.893-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23943 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.266-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:54.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="httpd-devel is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:110719"/>
          <criterion comment="httpd-tools is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:111285"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:110976"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:111584"/>
          <criterion comment="httpd is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:111441"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23942" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:1102: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2012:1102-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1102.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1178" ref_url="http://linux.oracle.com/cve/CVE-2012-1178.html" source="CVE"/>
        <reference ref_id="CVE-2012-2318" ref_url="http://linux.oracle.com/cve/CVE-2012-2318.html" source="CVE"/>
        <reference ref_id="CVE-2012-3374" ref_url="http://linux.oracle.com/cve/CVE-2012-3374.html" source="CVE"/>
        <description>Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:44.067-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.376-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:51.674-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23942 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:35.689-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:54.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110373"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110676"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110752"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:109775"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110463"/>
            <criterion comment="finch is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110328"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110694"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110487"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:110758"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110645"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110711"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110715"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110579"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110522"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110420"/>
            <criterion comment="finch is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110626"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110721"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110678"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:110653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23941" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1131: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2012:1131-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1131.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1013" ref_url="http://linux.oracle.com/cve/CVE-2012-1013.html" source="CVE"/>
        <reference ref_id="CVE-2012-1015" ref_url="http://linux.oracle.com/cve/CVE-2012-1015.html" source="CVE"/>
        <description>The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x before 1.10.3 attempts to calculate a checksum before verifying that the key type is appropriate for a checksum, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free, heap memory corruption, and daemon crash) via a crafted AS-REQ request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:51.587-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.287-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:51.489-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23941 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.489-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:54.303-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-server-ldap is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:110805"/>
          <criterion comment="krb5-devel is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:110750"/>
          <criterion comment="krb5-workstation is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:110737"/>
          <criterion comment="krb5-libs is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:110274"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:109894"/>
          <criterion comment="krb5-server is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:110892"/>
          <criterion comment="krb5 is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:110822"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23939" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0714: stunnel security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>stunnel</product>
        </affected>
        <reference ref_id="ELSA-2013:0714-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0714.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1762" ref_url="http://linux.oracle.com/cve/CVE-2013-1762.html" source="CVE"/>
        <description>stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:36.843-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:30.155-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:51.272-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23939 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.570-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:54.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="stunnel is earlier than 0:4.29-3.el6_4" test_ref="oval:org.mitre.oval:tst:111684"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23937" version="73" class="patch">
      <metadata>
        <title>ELSA-2012:1088: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1088-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1088.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1948" ref_url="http://linux.oracle.com/cve/CVE-2012-1948.html" source="CVE"/>
        <reference ref_id="CVE-2012-1950" ref_url="http://linux.oracle.com/cve/CVE-2012-1950.html" source="CVE"/>
        <reference ref_id="CVE-2012-1951" ref_url="http://linux.oracle.com/cve/CVE-2012-1951.html" source="CVE"/>
        <reference ref_id="CVE-2012-1952" ref_url="http://linux.oracle.com/cve/CVE-2012-1952.html" source="CVE"/>
        <reference ref_id="CVE-2012-1953" ref_url="http://linux.oracle.com/cve/CVE-2012-1953.html" source="CVE"/>
        <reference ref_id="CVE-2012-1954" ref_url="http://linux.oracle.com/cve/CVE-2012-1954.html" source="CVE"/>
        <reference ref_id="CVE-2012-1955" ref_url="http://linux.oracle.com/cve/CVE-2012-1955.html" source="CVE"/>
        <reference ref_id="CVE-2012-1957" ref_url="http://linux.oracle.com/cve/CVE-2012-1957.html" source="CVE"/>
        <reference ref_id="CVE-2012-1958" ref_url="http://linux.oracle.com/cve/CVE-2012-1958.html" source="CVE"/>
        <reference ref_id="CVE-2012-1959" ref_url="http://linux.oracle.com/cve/CVE-2012-1959.html" source="CVE"/>
        <reference ref_id="CVE-2012-1961" ref_url="http://linux.oracle.com/cve/CVE-2012-1961.html" source="CVE"/>
        <reference ref_id="CVE-2012-1962" ref_url="http://linux.oracle.com/cve/CVE-2012-1962.html" source="CVE"/>
        <reference ref_id="CVE-2012-1963" ref_url="http://linux.oracle.com/cve/CVE-2012-1963.html" source="CVE"/>
        <reference ref_id="CVE-2012-1964" ref_url="http://linux.oracle.com/cve/CVE-2012-1964.html" source="CVE"/>
        <reference ref_id="CVE-2012-1965" ref_url="http://linux.oracle.com/cve/CVE-2012-1965.html" source="CVE"/>
        <reference ref_id="CVE-2012-1966" ref_url="http://linux.oracle.com/cve/CVE-2012-1966.html" source="CVE"/>
        <reference ref_id="CVE-2012-1967" ref_url="http://linux.oracle.com/cve/CVE-2012-1967.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:50.245-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:29.789-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:50.605-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23937 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.998-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:53.639-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:110668"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:110357"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el5_8" test_ref="oval:org.mitre.oval:tst:110603"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:110270"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:110656"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:110415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23936" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:1590: libtiff security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2012:1590-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1590.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3401" ref_url="http://linux.oracle.com/cve/CVE-2012-3401.html" source="CVE"/>
        <reference ref_id="CVE-2012-4447" ref_url="http://linux.oracle.com/cve/CVE-2012-4447.html" source="CVE"/>
        <reference ref_id="CVE-2012-4564" ref_url="http://linux.oracle.com/cve/CVE-2012-4564.html" source="CVE"/>
        <reference ref_id="CVE-2012-5581" ref_url="http://linux.oracle.com/cve/CVE-2012-5581.html" source="CVE"/>
        <description>Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:00.130-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:29.662-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:50.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23936 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.168-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:53.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:111247"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:111059"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:110879"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:110722"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:111208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23933" version="85" class="patch">
      <metadata>
        <title>ELSA-2013:0245: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0245-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0245.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0424" ref_url="http://linux.oracle.com/cve/CVE-2013-0424.html" source="CVE"/>
        <reference ref_id="CVE-2013-0425" ref_url="http://linux.oracle.com/cve/CVE-2013-0425.html" source="CVE"/>
        <reference ref_id="CVE-2013-0426" ref_url="http://linux.oracle.com/cve/CVE-2013-0426.html" source="CVE"/>
        <reference ref_id="CVE-2013-0427" ref_url="http://linux.oracle.com/cve/CVE-2013-0427.html" source="CVE"/>
        <reference ref_id="CVE-2013-0428" ref_url="http://linux.oracle.com/cve/CVE-2013-0428.html" source="CVE"/>
        <reference ref_id="CVE-2013-0429" ref_url="http://linux.oracle.com/cve/CVE-2013-0429.html" source="CVE"/>
        <reference ref_id="CVE-2013-0432" ref_url="http://linux.oracle.com/cve/CVE-2013-0432.html" source="CVE"/>
        <reference ref_id="CVE-2013-0433" ref_url="http://linux.oracle.com/cve/CVE-2013-0433.html" source="CVE"/>
        <reference ref_id="CVE-2013-0434" ref_url="http://linux.oracle.com/cve/CVE-2013-0434.html" source="CVE"/>
        <reference ref_id="CVE-2013-0435" ref_url="http://linux.oracle.com/cve/CVE-2013-0435.html" source="CVE"/>
        <reference ref_id="CVE-2013-0440" ref_url="http://linux.oracle.com/cve/CVE-2013-0440.html" source="CVE"/>
        <reference ref_id="CVE-2013-0441" ref_url="http://linux.oracle.com/cve/CVE-2013-0441.html" source="CVE"/>
        <reference ref_id="CVE-2013-0442" ref_url="http://linux.oracle.com/cve/CVE-2013-0442.html" source="CVE"/>
        <reference ref_id="CVE-2013-0443" ref_url="http://linux.oracle.com/cve/CVE-2013-0443.html" source="CVE"/>
        <reference ref_id="CVE-2013-0445" ref_url="http://linux.oracle.com/cve/CVE-2013-0445.html" source="CVE"/>
        <reference ref_id="CVE-2013-0450" ref_url="http://linux.oracle.com/cve/CVE-2013-0450.html" source="CVE"/>
        <reference ref_id="CVE-2013-1475" ref_url="http://linux.oracle.com/cve/CVE-2013-1475.html" source="CVE"/>
        <reference ref_id="CVE-2013-1476" ref_url="http://linux.oracle.com/cve/CVE-2013-1476.html" source="CVE"/>
        <reference ref_id="CVE-2013-1478" ref_url="http://linux.oracle.com/cve/CVE-2013-1478.html" source="CVE"/>
        <reference ref_id="CVE-2013-1480" ref_url="http://linux.oracle.com/cve/CVE-2013-1480.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.	 NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:19.244-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:29.173-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:49.506-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23933 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:37.326-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:52.920-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:111376"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:111387"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:111019"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:111281"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:110811"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23932" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0841: abrt, libreport, btparser, and python-meh security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>abrt</product>
          <product>btparser</product>
          <product>libreport</product>
          <product>python-meh</product>
        </affected>
        <reference ref_id="ELSA-2012:0841-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0841.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4088" ref_url="http://linux.oracle.com/cve/CVE-2011-4088.html" source="CVE"/>
        <reference ref_id="CVE-2012-1106" ref_url="http://linux.oracle.com/cve/CVE-2012-1106.html" source="CVE"/>
        <description>The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:44.036-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:29.037-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:49.310-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23932 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:36.825-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:52.703-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="python-meh is earlier than 0:0.12.1-3.el6" test_ref="oval:org.mitre.oval:tst:109763"/>
          <criterion comment="btparser-python is earlier than 0:0.16-3.el6" test_ref="oval:org.mitre.oval:tst:110511"/>
          <criterion comment="btparser is earlier than 0:0.16-3.el6" test_ref="oval:org.mitre.oval:tst:110548"/>
          <criterion comment="btparser-devel is earlier than 0:0.16-3.el6" test_ref="oval:org.mitre.oval:tst:110378"/>
          <criterion comment="abrt-desktop is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110578"/>
          <criterion comment="abrt-gui is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110222"/>
          <criterion comment="abrt is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110169"/>
          <criterion comment="abrt-devel is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110398"/>
          <criterion comment="abrt-addon-kerneloops is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110583"/>
          <criterion comment="abrt-tui is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110244"/>
          <criterion comment="abrt-addon-vmcore is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110580"/>
          <criterion comment="abrt-addon-ccpp is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110050"/>
          <criterion comment="abrt-addon-python is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110574"/>
          <criterion comment="abrt-libs is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110517"/>
          <criterion comment="abrt-cli is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:110451"/>
          <criterion comment="libreport-plugin-mailx is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110422"/>
          <criterion comment="libreport-plugin-rhtsupport is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110242"/>
          <criterion comment="libreport-gtk-devel is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110419"/>
          <criterion comment="libreport-python is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110561"/>
          <criterion comment="libreport-cli is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110324"/>
          <criterion comment="libreport is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110157"/>
          <criterion comment="libreport-plugin-reportuploader is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110262"/>
          <criterion comment="libreport-newt is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110376"/>
          <criterion comment="libreport-gtk is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110531"/>
          <criterion comment="libreport-plugin-kerneloops is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110535"/>
          <criterion comment="libreport-devel is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110575"/>
          <criterion comment="libreport-plugin-logger is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:109866"/>
          <criterion comment="libreport-plugin-bugzilla is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:110402"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23931" version="69" class="patch">
      <metadata>
        <title>ELSA-2012:1462: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2012:1462-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1462.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0540" ref_url="http://linux.oracle.com/cve/CVE-2012-0540.html" source="CVE"/>
        <reference ref_id="CVE-2012-1688" ref_url="http://linux.oracle.com/cve/CVE-2012-1688.html" source="CVE"/>
        <reference ref_id="CVE-2012-1689" ref_url="http://linux.oracle.com/cve/CVE-2012-1689.html" source="CVE"/>
        <reference ref_id="CVE-2012-1690" ref_url="http://linux.oracle.com/cve/CVE-2012-1690.html" source="CVE"/>
        <reference ref_id="CVE-2012-1703" ref_url="http://linux.oracle.com/cve/CVE-2012-1703.html" source="CVE"/>
        <reference ref_id="CVE-2012-1734" ref_url="http://linux.oracle.com/cve/CVE-2012-1734.html" source="CVE"/>
        <reference ref_id="CVE-2012-2749" ref_url="http://linux.oracle.com/cve/CVE-2012-2749.html" source="CVE"/>
        <reference ref_id="CVE-2012-3150" ref_url="http://linux.oracle.com/cve/CVE-2012-3150.html" source="CVE"/>
        <reference ref_id="CVE-2012-3158" ref_url="http://linux.oracle.com/cve/CVE-2012-3158.html" source="CVE"/>
        <reference ref_id="CVE-2012-3160" ref_url="http://linux.oracle.com/cve/CVE-2012-3160.html" source="CVE"/>
        <reference ref_id="CVE-2012-3163" ref_url="http://linux.oracle.com/cve/CVE-2012-3163.html" source="CVE"/>
        <reference ref_id="CVE-2012-3166" ref_url="http://linux.oracle.com/cve/CVE-2012-3166.html" source="CVE"/>
        <reference ref_id="CVE-2012-3167" ref_url="http://linux.oracle.com/cve/CVE-2012-3167.html" source="CVE"/>
        <reference ref_id="CVE-2012-3173" ref_url="http://linux.oracle.com/cve/CVE-2012-3173.html" source="CVE"/>
        <reference ref_id="CVE-2012-3177" ref_url="http://linux.oracle.com/cve/CVE-2012-3177.html" source="CVE"/>
        <reference ref_id="CVE-2012-3180" ref_url="http://linux.oracle.com/cve/CVE-2012-3180.html" source="CVE"/>
        <reference ref_id="CVE-2012-3197" ref_url="http://linux.oracle.com/cve/CVE-2012-3197.html" source="CVE"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replication.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:14.785-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:28.676-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:48.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23931 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.449-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:52.159-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:110744"/>
          <criterion comment="mysql-server is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:110824"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:111030"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:111024"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:111202"/>
          <criterion comment="mysql-test is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:111215"/>
          <criterion comment="mysql is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:111029"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:110655"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23930" version="29" class="patch">
      <metadata>
        <title>ELSA-2013:1173: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:1173-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1173.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6544" ref_url="http://linux.oracle.com/cve/CVE-2012-6544.html" source="CVE"/>
        <reference ref_id="CVE-2013-2146" ref_url="http://linux.oracle.com/cve/CVE-2013-2146.html" source="CVE"/>
        <reference ref_id="CVE-2013-2206" ref_url="http://linux.oracle.com/cve/CVE-2013-2206.html" source="CVE"/>
        <reference ref_id="CVE-2013-2224" ref_url="http://linux.oracle.com/cve/CVE-2013-2224.html" source="CVE"/>
        <reference ref_id="CVE-2013-2232" ref_url="http://linux.oracle.com/cve/CVE-2013-2232.html" source="CVE"/>
        <reference ref_id="CVE-2013-2237" ref_url="http://linux.oracle.com/cve/CVE-2013-2237.html" source="CVE"/>
        <description>The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:00.333-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:28.492-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:48.311-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23930 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:37.685-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:51.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:112272"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:112083"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:112206"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:112256"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:111545"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:112303"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:112401"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:112210"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:112231"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:111924"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:111871"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:112189"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23929" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0243: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:0243-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0243.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0633" ref_url="http://linux.oracle.com/cve/CVE-2013-0633.html" source="CVE"/>
        <reference ref_id="CVE-2013-0634" ref_url="http://linux.oracle.com/cve/CVE-2013-0634.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:30.049-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:28.373-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:48.176-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23929 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.237-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:51.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.262-1.el6" test_ref="oval:org.mitre.oval:tst:110430"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23927" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0831: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2013:0831-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0831.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1962" ref_url="http://linux.oracle.com/cve/CVE-2013-1962.html" source="CVE"/>
        <description>The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of requests "to list all volumes for the particular pool."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:43.830-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:28.298-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:48.074-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23927 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.453-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:51.648-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:111959"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:111839"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:112044"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:112082"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:111516"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23926" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1054: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2012:1054-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1054.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2088" ref_url="http://linux.oracle.com/cve/CVE-2012-2088.html" source="CVE"/>
        <reference ref_id="CVE-2012-2113" ref_url="http://linux.oracle.com/cve/CVE-2012-2113.html" source="CVE"/>
        <description>Multiple integer overflows in tiff2pdf in libtiff before 4.0.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:47.393-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:28.200-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:47.944-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23926 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.560-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:51.526-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:110618"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:110740"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:110755"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:110512"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:110766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23925" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0753: icedtea-web security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference ref_id="ELSA-2013:0753-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0753.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1926" ref_url="http://linux.oracle.com/cve/CVE-2013-1926.html" source="CVE"/>
        <reference ref_id="CVE-2013-1927" ref_url="http://linux.oracle.com/cve/CVE-2013-1927.html" source="CVE"/>
        <description>The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:37.229-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:28.117-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:47.817-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23925 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:38.741-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:51.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.2.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:111326"/>
          <criterion comment="icedtea-web is earlier than 0:1.2.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:112035"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23924" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:1801: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:1801-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1801.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2141" ref_url="http://linux.oracle.com/cve/CVE-2013-2141.html" source="CVE"/>
        <reference ref_id="CVE-2013-4470" ref_url="http://linux.oracle.com/cve/CVE-2013-4470.html" source="CVE"/>
        <reference ref_id="CVE-2013-6367" ref_url="http://linux.oracle.com/cve/CVE-2013-6367.html" source="CVE"/>
        <reference ref_id="CVE-2013-6368" ref_url="http://linux.oracle.com/cve/CVE-2013-6368.html" source="CVE"/>
        <description>The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:04.936-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:27.982-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:47.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23924 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:35.486-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:51.243-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:111710"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:111888"/>
          <criterion comment="kernel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112506"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112367"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112444"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112424"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:111951"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112565"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112537"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112607"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112676"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112335"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:112588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23922" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1512: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:1512-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1512.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5134" ref_url="http://linux.oracle.com/cve/CVE-2012-5134.html" source="CVE"/>
        <description>Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:05.640-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:27.810-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:47.308-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23922 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.066-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:51.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:111126"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:111008"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:111025"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:110997"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:111188"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:110336"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:111181"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23921" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1551: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2012:1551-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1551.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5611" ref_url="http://linux.oracle.com/cve/CVE-2012-5611.html" source="CVE"/>
        <description>Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:08.609-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:27.727-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:47.199-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23921 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.662-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:50.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-server is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:111304"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:111120"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:111315"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:111324"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:111010"/>
          <criterion comment="mysql-test is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:110982"/>
          <criterion comment="mysql is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:111267"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:111275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23920" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0942: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2013:0942-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0942.html" source="VENDOR"/>
        <reference ref_id="CVE-2002-2443" ref_url="http://linux.oracle.com/cve/CVE-2002-2443.html" source="CVE"/>
        <description>schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:07.046-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:27.622-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:47.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23920 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.998-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:50.814-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:111862"/>
            <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:111932"/>
            <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:112091"/>
            <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:112170"/>
            <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:112146"/>
            <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:111885"/>
            <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:112181"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112227"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112088"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:111893"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112087"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112176"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:112158"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23919" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1818: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:1818-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1818.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5331" ref_url="http://linux.oracle.com/cve/CVE-2013-5331.html" source="CVE"/>
        <reference ref_id="CVE-2013-5332" ref_url="http://linux.oracle.com/cve/CVE-2013-5332.html" source="CVE"/>
        <description>Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK &amp; Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:01.761-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:27.542-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:46.943-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23919 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.417-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:50.633-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.332-1.el6" test_ref="oval:org.mitre.oval:tst:112290"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23917" version="49" class="patch">
      <metadata>
        <title>ELSA-2013:1051: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:1051-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1051.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6548" ref_url="http://linux.oracle.com/cve/CVE-2012-6548.html" source="CVE"/>
        <reference ref_id="CVE-2013-0914" ref_url="http://linux.oracle.com/cve/CVE-2013-0914.html" source="CVE"/>
        <reference ref_id="CVE-2013-1848" ref_url="http://linux.oracle.com/cve/CVE-2013-1848.html" source="CVE"/>
        <reference ref_id="CVE-2013-2128" ref_url="http://linux.oracle.com/cve/CVE-2013-2128.html" source="CVE"/>
        <reference ref_id="CVE-2013-2634" ref_url="http://linux.oracle.com/cve/CVE-2013-2634.html" source="CVE"/>
        <reference ref_id="CVE-2013-2635" ref_url="http://linux.oracle.com/cve/CVE-2013-2635.html" source="CVE"/>
        <reference ref_id="CVE-2013-2852" ref_url="http://linux.oracle.com/cve/CVE-2013-2852.html" source="CVE"/>
        <reference ref_id="CVE-2013-3222" ref_url="http://linux.oracle.com/cve/CVE-2013-3222.html" source="CVE"/>
        <reference ref_id="CVE-2013-3224" ref_url="http://linux.oracle.com/cve/CVE-2013-3224.html" source="CVE"/>
        <reference ref_id="CVE-2013-3225" ref_url="http://linux.oracle.com/cve/CVE-2013-3225.html" source="CVE"/>
        <reference ref_id="CVE-2013-3301" ref_url="http://linux.oracle.com/cve/CVE-2013-3301.html" source="CVE"/>
        <description>The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:05.907-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:27.170-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:46.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23917 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.704-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:50.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112065"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:111591"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112097"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112059"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112090"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112168"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112173"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:111422"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112127"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112246"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112148"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:112270"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23916" version="37" class="patch">
      <metadata>
        <title>ELSA-2013:1812: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2013:1812-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1812.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0772" ref_url="http://linux.oracle.com/cve/CVE-2013-0772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5609" ref_url="http://linux.oracle.com/cve/CVE-2013-5609.html" source="CVE"/>
        <reference ref_id="CVE-2013-5612" ref_url="http://linux.oracle.com/cve/CVE-2013-5612.html" source="CVE"/>
        <reference ref_id="CVE-2013-5613" ref_url="http://linux.oracle.com/cve/CVE-2013-5613.html" source="CVE"/>
        <reference ref_id="CVE-2013-5614" ref_url="http://linux.oracle.com/cve/CVE-2013-5614.html" source="CVE"/>
        <reference ref_id="CVE-2013-5616" ref_url="http://linux.oracle.com/cve/CVE-2013-5616.html" source="CVE"/>
        <reference ref_id="CVE-2013-5618" ref_url="http://linux.oracle.com/cve/CVE-2013-5618.html" source="CVE"/>
        <reference ref_id="CVE-2013-6671" ref_url="http://linux.oracle.com/cve/CVE-2013-6671.html" source="CVE"/>
        <description>The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:13.582-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:26.967-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:46.080-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23916 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.972-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:49.634-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:112384"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:112239"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23915" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0551: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2013:0551-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0551.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0640" ref_url="http://linux.oracle.com/cve/CVE-2013-0640.html" source="CVE"/>
        <reference ref_id="CVE-2013-0641" ref_url="http://linux.oracle.com/cve/CVE-2013-0641.html" source="CVE"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:41.777-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:26.884-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:45.948-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23915 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:40.873-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:49.461-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="acroread is earlier than 0:9.5.4-1.el6" test_ref="oval:org.mitre.oval:tst:111763"/>
          <criterion comment="acroread-plugin is earlier than 0:9.5.4-1.el6" test_ref="oval:org.mitre.oval:tst:111748"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23914" version="13" class="patch">
      <metadata>
        <title>ELSA-2014:0103: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2014:0103-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0103.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6458" ref_url="http://linux.oracle.com/cve/CVE-2013-6458.html" source="CVE"/>
        <reference ref_id="CVE-2014-1447" ref_url="http://linux.oracle.com/cve/CVE-2014-1447.html" source="CVE"/>
        <description>Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:37.409-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:26.776-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:45.779-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23914 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.048-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:49.243-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:112098"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:112070"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:112627"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:112695"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:112777"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23913" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0531: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2013:0531-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0531.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <reference ref_id="CVE-2013-1487" ref_url="http://linux.oracle.com/cve/CVE-2013-1487.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 and earlier and 6 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:46.890-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:26.694-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:45.576-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23913 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:38.650-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:49.092-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111367"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111414"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111636"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111622"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111725"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23912" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0588: gnutls security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2013:0588-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0588.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1619" ref_url="http://linux.oracle.com/cve/CVE-2013-1619.html" source="CVE"/>
        <description>The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:43.117-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:26.619-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:45.454-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23912 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.332-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:48.947-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111740"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111338"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111253"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111694"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:111054"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:111690"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:111761"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23911" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0292: 389-ds-base security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference ref_id="ELSA-2014:0292-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0292.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0132" ref_url="http://linux.oracle.com/cve/CVE-2014-0132.html" source="CVE"/>
        <description>The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:26.563-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:06:45.344-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:09.735-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23911 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:22.998-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:04.967-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-32.el6_5" test_ref="oval:org.mitre.oval:tst:113537"/>
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-32.el6_5" test_ref="oval:org.mitre.oval:tst:113070"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-32.el6_5" test_ref="oval:org.mitre.oval:tst:113648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23909" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0587: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2013:0587-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0587.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4929" ref_url="http://linux.oracle.com/cve/CVE-2012-4929.html" source="CVE"/>
        <reference ref_id="CVE-2013-0166" ref_url="http://linux.oracle.com/cve/CVE-2013-0166.html" source="CVE"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <description>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:38.746-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:26.517-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:45.188-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23909 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.866-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:48.727-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:111589"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:111730"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:111549"/>
            <criterion comment="openssl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:111490"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:111691"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:111455"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:111485"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23908" version="105" class="patch">
      <metadata>
        <title>ELSA-2013:0150: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2013:0150-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0150.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1530" ref_url="http://linux.oracle.com/cve/CVE-2012-1530.html" source="CVE"/>
        <reference ref_id="CVE-2013-0601" ref_url="http://linux.oracle.com/cve/CVE-2013-0601.html" source="CVE"/>
        <reference ref_id="CVE-2013-0602" ref_url="http://linux.oracle.com/cve/CVE-2013-0602.html" source="CVE"/>
        <reference ref_id="CVE-2013-0603" ref_url="http://linux.oracle.com/cve/CVE-2013-0603.html" source="CVE"/>
        <reference ref_id="CVE-2013-0604" ref_url="http://linux.oracle.com/cve/CVE-2013-0604.html" source="CVE"/>
        <reference ref_id="CVE-2013-0605" ref_url="http://linux.oracle.com/cve/CVE-2013-0605.html" source="CVE"/>
        <reference ref_id="CVE-2013-0606" ref_url="http://linux.oracle.com/cve/CVE-2013-0606.html" source="CVE"/>
        <reference ref_id="CVE-2013-0607" ref_url="http://linux.oracle.com/cve/CVE-2013-0607.html" source="CVE"/>
        <reference ref_id="CVE-2013-0608" ref_url="http://linux.oracle.com/cve/CVE-2013-0608.html" source="CVE"/>
        <reference ref_id="CVE-2013-0609" ref_url="http://linux.oracle.com/cve/CVE-2013-0609.html" source="CVE"/>
        <reference ref_id="CVE-2013-0610" ref_url="http://linux.oracle.com/cve/CVE-2013-0610.html" source="CVE"/>
        <reference ref_id="CVE-2013-0611" ref_url="http://linux.oracle.com/cve/CVE-2013-0611.html" source="CVE"/>
        <reference ref_id="CVE-2013-0612" ref_url="http://linux.oracle.com/cve/CVE-2013-0612.html" source="CVE"/>
        <reference ref_id="CVE-2013-0613" ref_url="http://linux.oracle.com/cve/CVE-2013-0613.html" source="CVE"/>
        <reference ref_id="CVE-2013-0614" ref_url="http://linux.oracle.com/cve/CVE-2013-0614.html" source="CVE"/>
        <reference ref_id="CVE-2013-0615" ref_url="http://linux.oracle.com/cve/CVE-2013-0615.html" source="CVE"/>
        <reference ref_id="CVE-2013-0616" ref_url="http://linux.oracle.com/cve/CVE-2013-0616.html" source="CVE"/>
        <reference ref_id="CVE-2013-0617" ref_url="http://linux.oracle.com/cve/CVE-2013-0617.html" source="CVE"/>
        <reference ref_id="CVE-2013-0618" ref_url="http://linux.oracle.com/cve/CVE-2013-0618.html" source="CVE"/>
        <reference ref_id="CVE-2013-0619" ref_url="http://linux.oracle.com/cve/CVE-2013-0619.html" source="CVE"/>
        <reference ref_id="CVE-2013-0620" ref_url="http://linux.oracle.com/cve/CVE-2013-0620.html" source="CVE"/>
        <reference ref_id="CVE-2013-0621" ref_url="http://linux.oracle.com/cve/CVE-2013-0621.html" source="CVE"/>
        <reference ref_id="CVE-2013-0623" ref_url="http://linux.oracle.com/cve/CVE-2013-0623.html" source="CVE"/>
        <reference ref_id="CVE-2013-0626" ref_url="http://linux.oracle.com/cve/CVE-2013-0626.html" source="CVE"/>
        <reference ref_id="CVE-2013-1376" ref_url="http://linux.oracle.com/cve/CVE-2013-1376.html" source="CVE"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0606, CVE-2013-0612, CVE-2013-0615, CVE-2013-0617, and CVE-2013-0621.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:33.583-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:25.999-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:44.155-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23908 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:36.258-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:47.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="acroread is earlier than 0:9.5.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111229"/>
          <criterion comment="acroread-plugin is earlier than 0:9.5.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111239"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23907" version="85" class="patch">
      <metadata>
        <title>ELSA-2012:1386: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2012:1386-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-1386.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3216" ref_url="http://linux.oracle.com/cve/CVE-2012-3216.html" source="CVE"/>
        <reference ref_id="CVE-2012-4416" ref_url="http://linux.oracle.com/cve/CVE-2012-4416.html" source="CVE"/>
        <reference ref_id="CVE-2012-5068" ref_url="http://linux.oracle.com/cve/CVE-2012-5068.html" source="CVE"/>
        <reference ref_id="CVE-2012-5069" ref_url="http://linux.oracle.com/cve/CVE-2012-5069.html" source="CVE"/>
        <reference ref_id="CVE-2012-5070" ref_url="http://linux.oracle.com/cve/CVE-2012-5070.html" source="CVE"/>
        <reference ref_id="CVE-2012-5071" ref_url="http://linux.oracle.com/cve/CVE-2012-5071.html" source="CVE"/>
        <reference ref_id="CVE-2012-5072" ref_url="http://linux.oracle.com/cve/CVE-2012-5072.html" source="CVE"/>
        <reference ref_id="CVE-2012-5073" ref_url="http://linux.oracle.com/cve/CVE-2012-5073.html" source="CVE"/>
        <reference ref_id="CVE-2012-5074" ref_url="http://linux.oracle.com/cve/CVE-2012-5074.html" source="CVE"/>
        <reference ref_id="CVE-2012-5075" ref_url="http://linux.oracle.com/cve/CVE-2012-5075.html" source="CVE"/>
        <reference ref_id="CVE-2012-5076" ref_url="http://linux.oracle.com/cve/CVE-2012-5076.html" source="CVE"/>
        <reference ref_id="CVE-2012-5077" ref_url="http://linux.oracle.com/cve/CVE-2012-5077.html" source="CVE"/>
        <reference ref_id="CVE-2012-5079" ref_url="http://linux.oracle.com/cve/CVE-2012-5079.html" source="CVE"/>
        <reference ref_id="CVE-2012-5081" ref_url="http://linux.oracle.com/cve/CVE-2012-5081.html" source="CVE"/>
        <reference ref_id="CVE-2012-5084" ref_url="http://linux.oracle.com/cve/CVE-2012-5084.html" source="CVE"/>
        <reference ref_id="CVE-2012-5085" ref_url="http://linux.oracle.com/cve/CVE-2012-5085.html" source="CVE"/>
        <reference ref_id="CVE-2012-5086" ref_url="http://linux.oracle.com/cve/CVE-2012-5086.html" source="CVE"/>
        <reference ref_id="CVE-2012-5087" ref_url="http://linux.oracle.com/cve/CVE-2012-5087.html" source="CVE"/>
        <reference ref_id="CVE-2012-5088" ref_url="http://linux.oracle.com/cve/CVE-2012-5088.html" source="CVE"/>
        <reference ref_id="CVE-2012-5089" ref_url="http://linux.oracle.com/cve/CVE-2012-5089.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:01.307-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:25.863-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:44.046-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23907 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:41.538-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:47.419-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:110998"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:110282"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:110467"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:110779"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:111080"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23906" version="41" class="patch">
      <metadata>
        <title>ELSA-2012:1046: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:1046-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1046.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2950" ref_url="http://linux.oracle.com/cve/CVE-2010-2950.html" source="CVE"/>
        <reference ref_id="CVE-2011-4153" ref_url="http://linux.oracle.com/cve/CVE-2011-4153.html" source="CVE"/>
        <reference ref_id="CVE-2012-0057" ref_url="http://linux.oracle.com/cve/CVE-2012-0057.html" source="CVE"/>
        <reference ref_id="CVE-2012-0781" ref_url="http://linux.oracle.com/cve/CVE-2012-0781.html" source="CVE"/>
        <reference ref_id="CVE-2012-0789" ref_url="http://linux.oracle.com/cve/CVE-2012-0789.html" source="CVE"/>
        <reference ref_id="CVE-2012-1172" ref_url="http://linux.oracle.com/cve/CVE-2012-1172.html" source="CVE"/>
        <reference ref_id="CVE-2012-2143" ref_url="http://linux.oracle.com/cve/CVE-2012-2143.html" source="CVE"/>
        <reference ref_id="CVE-2012-2336" ref_url="http://linux.oracle.com/cve/CVE-2012-2336.html" source="CVE"/>
        <reference ref_id="CVE-2012-2386" ref_url="http://linux.oracle.com/cve/CVE-2012-2386.html" source="CVE"/>
        <description>Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:42.081-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:25.562-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:43.566-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23906 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:38.899-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:46.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php-pdo is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110642"/>
          <criterion comment="php-common is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110606"/>
          <criterion comment="php-enchant is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110549"/>
          <criterion comment="php-embedded is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110611"/>
          <criterion comment="php-snmp is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110391"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110411"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110525"/>
          <criterion comment="php-devel is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:109767"/>
          <criterion comment="php-recode is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:109741"/>
          <criterion comment="php is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110571"/>
          <criterion comment="php-imap is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110633"/>
          <criterion comment="php-gd is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110488"/>
          <criterion comment="php-odbc is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110528"/>
          <criterion comment="php-tidy is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110513"/>
          <criterion comment="php-soap is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110682"/>
          <criterion comment="php-mysql is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110196"/>
          <criterion comment="php-zts is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110651"/>
          <criterion comment="php-process is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110458"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110661"/>
          <criterion comment="php-intl is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110662"/>
          <criterion comment="php-ldap is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110075"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110221"/>
          <criterion comment="php-dba is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110691"/>
          <criterion comment="php-cli is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110118"/>
          <criterion comment="php-pspell is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110669"/>
          <criterion comment="php-xml is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:110667"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23903" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0874: mysql security and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2012:0874-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0874.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2102" ref_url="http://linux.oracle.com/cve/CVE-2012-2102.html" source="CVE"/>
        <description>MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:27.341-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:25.479-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:43.442-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23903 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:39.772-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:46.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:110483"/>
          <criterion comment="mysql-server is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:109796"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:110573"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:110051"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:110567"/>
          <criterion comment="mysql-test is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:109934"/>
          <criterion comment="mysql is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:110462"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:110576"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23901" version="133" class="patch">
      <metadata>
        <title>ELSA-2013:0822: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:0822-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0822.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-1488" ref_url="http://linux.oracle.com/cve/CVE-2013-1488.html" source="CVE"/>
        <reference ref_id="CVE-2013-1491" ref_url="http://linux.oracle.com/cve/CVE-2013-1491.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1540" ref_url="http://linux.oracle.com/cve/CVE-2013-1540.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1558" ref_url="http://linux.oracle.com/cve/CVE-2013-1558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1563" ref_url="http://linux.oracle.com/cve/CVE-2013-1563.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2394" ref_url="http://linux.oracle.com/cve/CVE-2013-2394.html" source="CVE"/>
        <reference ref_id="CVE-2013-2415" ref_url="http://linux.oracle.com/cve/CVE-2013-2415.html" source="CVE"/>
        <reference ref_id="CVE-2013-2416" ref_url="http://linux.oracle.com/cve/CVE-2013-2416.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2418" ref_url="http://linux.oracle.com/cve/CVE-2013-2418.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2422" ref_url="http://linux.oracle.com/cve/CVE-2013-2422.html" source="CVE"/>
        <reference ref_id="CVE-2013-2423" ref_url="http://linux.oracle.com/cve/CVE-2013-2423.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2426" ref_url="http://linux.oracle.com/cve/CVE-2013-2426.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2432" ref_url="http://linux.oracle.com/cve/CVE-2013-2432.html" source="CVE"/>
        <reference ref_id="CVE-2013-2433" ref_url="http://linux.oracle.com/cve/CVE-2013-2433.html" source="CVE"/>
        <reference ref_id="CVE-2013-2434" ref_url="http://linux.oracle.com/cve/CVE-2013-2434.html" source="CVE"/>
        <reference ref_id="CVE-2013-2435" ref_url="http://linux.oracle.com/cve/CVE-2013-2435.html" source="CVE"/>
        <reference ref_id="CVE-2013-2436" ref_url="http://linux.oracle.com/cve/CVE-2013-2436.html" source="CVE"/>
        <reference ref_id="CVE-2013-2438" ref_url="http://linux.oracle.com/cve/CVE-2013-2438.html" source="CVE"/>
        <reference ref_id="CVE-2013-2440" ref_url="http://linux.oracle.com/cve/CVE-2013-2440.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:44.601-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:24.685-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:42.041-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23901 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:38.439-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:46.540-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112001"/>
          <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111734"/>
          <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111770"/>
          <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111644"/>
          <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111553"/>
          <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111895"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23900" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1068: openjpeg security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openjpeg</product>
        </affected>
        <reference ref_id="ELSA-2012:1068-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1068.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-5030" ref_url="http://linux.oracle.com/cve/CVE-2009-5030.html" source="CVE"/>
        <reference ref_id="CVE-2012-3358" ref_url="http://linux.oracle.com/cve/CVE-2012-3358.html" source="CVE"/>
        <description>Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:45.142-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:24.550-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:41.901-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23900 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:42.211-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:46.361-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openjpeg-libs is earlier than 0:1.3-8.el6_3" test_ref="oval:org.mitre.oval:tst:110479"/>
          <criterion comment="openjpeg is earlier than 0:1.3-8.el6_3" test_ref="oval:org.mitre.oval:tst:109822"/>
          <criterion comment="openjpeg-devel is earlier than 0:1.3-8.el6_3" test_ref="oval:org.mitre.oval:tst:110734"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23899" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0939: xorg-x11-server security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2012:0939-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0939.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4028" ref_url="http://linux.oracle.com/cve/CVE-2011-4028.html" source="CVE"/>
        <reference ref_id="CVE-2011-4029" ref_url="http://linux.oracle.com/cve/CVE-2011-4029.html" source="CVE"/>
        <description>The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:29.959-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:24.422-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:41.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23899 - optimisation of Oracle Linux content" date="2014-05-05T17:22:00.913-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:23:36.623-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:46.151-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:110640"/>
          <criterion comment="xorg-x11-server-devel is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:110478"/>
          <criterion comment="xorg-x11-server-source is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:110190"/>
          <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:110607"/>
          <criterion comment="xorg-x11-server is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:110287"/>
          <criterion comment="xorg-x11-server-common is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:110440"/>
          <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:110582"/>
          <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:110404"/>
          <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:110066"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23898" version="5" class="patch">
      <metadata>
        <title>ELSA-2012:0973: nss, nss-util, and nspr security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
          <product>nss-util</product>
          <product>nspr</product>
        </affected>
        <reference ref_id="ELSA-2012:0973-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0973.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.
It was found that a Certificate Authority (CA) issued a subordinate CA
certificate to its customer, that could be used to issue certificates for
any name. This update renders the subordinate CA certificate as untrusted.
(BZ#798533)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
The nspr package has been upgraded to upstream version 4.9, which provides
a number of bug fixes and enhancements over the previous version.
(BZ#799193)
The nss-util package has been upgraded to upstream version 3.13.3, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#799192)
The nss package has been upgraded to upstream version 3.13.3, which
provides numerous bug fixes and enhancements over the previous version. In
particular, SSL 2.0 is now disabled by default, support for SHA-224 has
been added, PORT_ErrorToString and PORT_ErrorToName now return the error
message and symbolic name of an NSS error code, and NSS_GetVersion now
returns the NSS version string. (BZ#744070)
These updated nss, nss-util, and nspr packages also provide fixes for the
following bugs:
* A PEM module internal function did not clean up memory when detecting a
non-existent file name. Consequently, memory leaks in client code occurred.
The code has been improved to deallocate such temporary objects and as a
result the reported memory leakage is gone. (BZ#746632)
* Recent changes to NSS re-introduced a problem where applications could
not use multiple SSL client certificates in the same process. Therefore,
any attempt to run commands that worked with multiple SSL client
certificates, such as the "yum repolist" command, resulted in a
re-negotiation handshake failure. With this update, a revised patch
correcting this problem has been applied to NSS, and using multiple SSL
client certificates in the same process is now possible again. (BZ#761086)
* The PEM module did not fully initialize newly constructed objects with
function pointers set to NULL. Consequently, a segmentation violation in
libcurl was sometimes experienced while accessing a package repository.
With this update, the code has been changed to fully initialize newly
allocated objects. As a result, updates can now be installed without
problems. (BZ#768669)
* A lack-of-robustness flaw caused the administration server for Red Hat
Directory Server to terminate unexpectedly because the mod_nss module made
nss calls before initializing nss as per the documented API. With this
update, nss protects itself against being called before it has been
properly initialized by the caller. (BZ#784674)
* Compilation errors occurred with some compilers when compiling code
against NSS 3.13.1. The following error message was displayed:
pkcs11n.h:365:26: warning: "__GNUC_MINOR" is not defined
An upstream patch has been applied to improve the code and the problem no
longer occurs. (BZ#795693)
* Unexpected terminations were reported in the messaging daemon (qpidd)
included in Red Hat Enterprise MRG after a recent update to nss. This
occurred because qpidd made nss calls before initializing nss. These
updated packages prevent qpidd and other affected processes that call nss
without initializing as mandated by the API from crashing. (BZ#797426)
Users of NSS, NSPR, and nss-util are advised to upgrade to these updated
packages, which fix these issues and add these enhancements. After
installing this update, applications using NSS, NSPR, or nss-util must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:42.181-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:24.264-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:41.668-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23898 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:30.192-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:04.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nspr is earlier than 0:4.9-1.el6" test_ref="oval:org.mitre.oval:tst:110234"/>
          <criterion comment="nspr-devel is earlier than 0:4.9-1.el6" test_ref="oval:org.mitre.oval:tst:109928"/>
          <criterion comment="nss-util is earlier than 0:3.13.3-2.el6" test_ref="oval:org.mitre.oval:tst:109876"/>
          <criterion comment="nss-util-devel is earlier than 0:3.13.3-2.el6" test_ref="oval:org.mitre.oval:tst:110348"/>
          <criterion comment="nss-tools is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:109905"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:110442"/>
          <criterion comment="nss-sysinit is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:110143"/>
          <criterion comment="nss is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:110600"/>
          <criterion comment="nss-devel is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:110615"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23894" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:1459: gnupg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnupg2</product>
        </affected>
        <reference ref_id="ELSA-2013:1459-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1459.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6085" ref_url="http://linux.oracle.com/cve/CVE-2012-6085.html" source="CVE"/>
        <reference ref_id="CVE-2013-4351" ref_url="http://linux.oracle.com/cve/CVE-2013-4351.html" source="CVE"/>
        <reference ref_id="CVE-2013-4402" ref_url="http://linux.oracle.com/cve/CVE-2013-4402.html" source="CVE"/>
        <description>The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:06.641-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:24.151-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:41.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23894 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.379-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:45.909-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnupg2 is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:112194"/>
            <criterion comment="gnupg2-smime is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:112175"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="gnupg2 is earlier than 0:2.0.10-6.el5_10" test_ref="oval:org.mitre.oval:tst:112261"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23893" version="129" class="patch">
      <metadata>
        <title>ELSA-2012:1467: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2012:1467-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1467.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3544" ref_url="http://linux.oracle.com/cve/CVE-2011-3544.html" source="CVE"/>
        <reference ref_id="CVE-2012-1531" ref_url="http://linux.oracle.com/cve/CVE-2012-1531.html" source="CVE"/>
        <reference ref_id="CVE-2012-1532" ref_url="http://linux.oracle.com/cve/CVE-2012-1532.html" source="CVE"/>
        <reference ref_id="CVE-2012-1533" ref_url="http://linux.oracle.com/cve/CVE-2012-1533.html" source="CVE"/>
        <reference ref_id="CVE-2012-1718" ref_url="http://linux.oracle.com/cve/CVE-2012-1718.html" source="CVE"/>
        <reference ref_id="CVE-2012-3143" ref_url="http://linux.oracle.com/cve/CVE-2012-3143.html" source="CVE"/>
        <reference ref_id="CVE-2012-3159" ref_url="http://linux.oracle.com/cve/CVE-2012-3159.html" source="CVE"/>
        <reference ref_id="CVE-2012-3216" ref_url="http://linux.oracle.com/cve/CVE-2012-3216.html" source="CVE"/>
        <reference ref_id="CVE-2012-4820" ref_url="http://linux.oracle.com/cve/CVE-2012-4820.html" source="CVE"/>
        <reference ref_id="CVE-2012-4821" ref_url="http://linux.oracle.com/cve/CVE-2012-4821.html" source="CVE"/>
        <reference ref_id="CVE-2012-4822" ref_url="http://linux.oracle.com/cve/CVE-2012-4822.html" source="CVE"/>
        <reference ref_id="CVE-2012-4823" ref_url="http://linux.oracle.com/cve/CVE-2012-4823.html" source="CVE"/>
        <reference ref_id="CVE-2012-5067" ref_url="http://linux.oracle.com/cve/CVE-2012-5067.html" source="CVE"/>
        <reference ref_id="CVE-2012-5069" ref_url="http://linux.oracle.com/cve/CVE-2012-5069.html" source="CVE"/>
        <reference ref_id="CVE-2012-5070" ref_url="http://linux.oracle.com/cve/CVE-2012-5070.html" source="CVE"/>
        <reference ref_id="CVE-2012-5071" ref_url="http://linux.oracle.com/cve/CVE-2012-5071.html" source="CVE"/>
        <reference ref_id="CVE-2012-5072" ref_url="http://linux.oracle.com/cve/CVE-2012-5072.html" source="CVE"/>
        <reference ref_id="CVE-2012-5073" ref_url="http://linux.oracle.com/cve/CVE-2012-5073.html" source="CVE"/>
        <reference ref_id="CVE-2012-5074" ref_url="http://linux.oracle.com/cve/CVE-2012-5074.html" source="CVE"/>
        <reference ref_id="CVE-2012-5075" ref_url="http://linux.oracle.com/cve/CVE-2012-5075.html" source="CVE"/>
        <reference ref_id="CVE-2012-5076" ref_url="http://linux.oracle.com/cve/CVE-2012-5076.html" source="CVE"/>
        <reference ref_id="CVE-2012-5077" ref_url="http://linux.oracle.com/cve/CVE-2012-5077.html" source="CVE"/>
        <reference ref_id="CVE-2012-5079" ref_url="http://linux.oracle.com/cve/CVE-2012-5079.html" source="CVE"/>
        <reference ref_id="CVE-2012-5081" ref_url="http://linux.oracle.com/cve/CVE-2012-5081.html" source="CVE"/>
        <reference ref_id="CVE-2012-5083" ref_url="http://linux.oracle.com/cve/CVE-2012-5083.html" source="CVE"/>
        <reference ref_id="CVE-2012-5084" ref_url="http://linux.oracle.com/cve/CVE-2012-5084.html" source="CVE"/>
        <reference ref_id="CVE-2012-5086" ref_url="http://linux.oracle.com/cve/CVE-2012-5086.html" source="CVE"/>
        <reference ref_id="CVE-2012-5087" ref_url="http://linux.oracle.com/cve/CVE-2012-5087.html" source="CVE"/>
        <reference ref_id="CVE-2012-5088" ref_url="http://linux.oracle.com/cve/CVE-2012-5088.html" source="CVE"/>
        <reference ref_id="CVE-2012-5089" ref_url="http://linux.oracle.com/cve/CVE-2012-5089.html" source="CVE"/>
        <reference ref_id="CVE-2013-1475" ref_url="http://linux.oracle.com/cve/CVE-2013-1475.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.java.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:15.437-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:23.358-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:40.870-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23893 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.906-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:45.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:111004"/>
          <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:111119"/>
          <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:111063"/>
          <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:110627"/>
          <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:110641"/>
          <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:111022"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23892" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0185: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2014:0185-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0185.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6466" ref_url="http://linux.oracle.com/cve/CVE-2013-6466.html" source="CVE"/>
        <description>Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:40.367-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:23.216-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:40.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23892 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.167-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:45.267-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:112563"/>
            <criterion comment="openswan is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:112526"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:112665"/>
            <criterion comment="openswan is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:112613"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23891" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0273: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0273-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0273.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:28.369-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:23.084-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:40.642-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23891 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:26:00.159-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:45.112-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:111218"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:111476"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:111380"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:111222"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:111378"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23889" version="41" class="patch">
      <metadata>
        <title>ELSA-2012:0743: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:0743-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0743.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0044" ref_url="http://linux.oracle.com/cve/CVE-2012-0044.html" source="CVE"/>
        <reference ref_id="CVE-2012-1179" ref_url="http://linux.oracle.com/cve/CVE-2012-1179.html" source="CVE"/>
        <reference ref_id="CVE-2012-2119" ref_url="http://linux.oracle.com/cve/CVE-2012-2119.html" source="CVE"/>
        <reference ref_id="CVE-2012-2121" ref_url="http://linux.oracle.com/cve/CVE-2012-2121.html" source="CVE"/>
        <reference ref_id="CVE-2012-2123" ref_url="http://linux.oracle.com/cve/CVE-2012-2123.html" source="CVE"/>
        <reference ref_id="CVE-2012-2136" ref_url="http://linux.oracle.com/cve/CVE-2012-2136.html" source="CVE"/>
        <reference ref_id="CVE-2012-2137" ref_url="http://linux.oracle.com/cve/CVE-2012-2137.html" source="CVE"/>
        <reference ref_id="CVE-2012-2372" ref_url="http://linux.oracle.com/cve/CVE-2012-2372.html" source="CVE"/>
        <reference ref_id="CVE-2012-2373" ref_url="http://linux.oracle.com/cve/CVE-2012-2373.html" source="CVE"/>
        <description>The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial of service (panic) via a crafted application that triggers a race condition.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:28.929-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:22.847-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:40.215-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23889 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:54.856-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:44.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110452"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110386"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110501"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110365"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110503"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110492"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110209"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110308"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110489"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110491"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110448"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:110344"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23888" version="49" class="patch">
      <metadata>
        <title>ELSA-2013:0217: mingw32-libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mingw32-libxml2</product>
        </affected>
        <reference ref_id="ELSA-2013:0217-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0217.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4008" ref_url="http://linux.oracle.com/cve/CVE-2010-4008.html" source="CVE"/>
        <reference ref_id="CVE-2010-4494" ref_url="http://linux.oracle.com/cve/CVE-2010-4494.html" source="CVE"/>
        <reference ref_id="CVE-2011-0216" ref_url="http://linux.oracle.com/cve/CVE-2011-0216.html" source="CVE"/>
        <reference ref_id="CVE-2011-1944" ref_url="http://linux.oracle.com/cve/CVE-2011-1944.html" source="CVE"/>
        <reference ref_id="CVE-2011-2821" ref_url="http://linux.oracle.com/cve/CVE-2011-2821.html" source="CVE"/>
        <reference ref_id="CVE-2011-2834" ref_url="http://linux.oracle.com/cve/CVE-2011-2834.html" source="CVE"/>
        <reference ref_id="CVE-2011-3102" ref_url="http://linux.oracle.com/cve/CVE-2011-3102.html" source="CVE"/>
        <reference ref_id="CVE-2011-3905" ref_url="http://linux.oracle.com/cve/CVE-2011-3905.html" source="CVE"/>
        <reference ref_id="CVE-2011-3919" ref_url="http://linux.oracle.com/cve/CVE-2011-3919.html" source="CVE"/>
        <reference ref_id="CVE-2012-0841" ref_url="http://linux.oracle.com/cve/CVE-2012-0841.html" source="CVE"/>
        <reference ref_id="CVE-2012-5134" ref_url="http://linux.oracle.com/cve/CVE-2012-5134.html" source="CVE"/>
        <description>Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:26.313-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:22.545-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:39.724-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23888 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:53.346-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:44.320-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mingw32-libxml2 is earlier than 0:2.7.6-6.el6_3" test_ref="oval:org.mitre.oval:tst:110812"/>
          <criterion comment="mingw32-libxml2-static is earlier than 0:2.7.6-6.el6_3" test_ref="oval:org.mitre.oval:tst:111151"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23887" version="121" class="patch">
      <metadata>
        <title>ELSA-2013:0957: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0957-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0957.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2449" ref_url="http://linux.oracle.com/cve/CVE-2013-2449.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2458" ref_url="http://linux.oracle.com/cve/CVE-2013-2458.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2460" ref_url="http://linux.oracle.com/cve/CVE-2013-2460.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.	NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:07.655-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:21.856-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:38.588-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23887 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:56.722-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:43.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:112118"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:112177"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:112192"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:112043"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:111277"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23886" version="57" class="patch">
      <metadata>
        <title>ELSA-2013:0825: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:0825-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0825.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2728" ref_url="http://linux.oracle.com/cve/CVE-2013-2728.html" source="CVE"/>
        <reference ref_id="CVE-2013-3324" ref_url="http://linux.oracle.com/cve/CVE-2013-3324.html" source="CVE"/>
        <reference ref_id="CVE-2013-3325" ref_url="http://linux.oracle.com/cve/CVE-2013-3325.html" source="CVE"/>
        <reference ref_id="CVE-2013-3326" ref_url="http://linux.oracle.com/cve/CVE-2013-3326.html" source="CVE"/>
        <reference ref_id="CVE-2013-3327" ref_url="http://linux.oracle.com/cve/CVE-2013-3327.html" source="CVE"/>
        <reference ref_id="CVE-2013-3328" ref_url="http://linux.oracle.com/cve/CVE-2013-3328.html" source="CVE"/>
        <reference ref_id="CVE-2013-3329" ref_url="http://linux.oracle.com/cve/CVE-2013-3329.html" source="CVE"/>
        <reference ref_id="CVE-2013-3330" ref_url="http://linux.oracle.com/cve/CVE-2013-3330.html" source="CVE"/>
        <reference ref_id="CVE-2013-3331" ref_url="http://linux.oracle.com/cve/CVE-2013-3331.html" source="CVE"/>
        <reference ref_id="CVE-2013-3332" ref_url="http://linux.oracle.com/cve/CVE-2013-3332.html" source="CVE"/>
        <reference ref_id="CVE-2013-3333" ref_url="http://linux.oracle.com/cve/CVE-2013-3333.html" source="CVE"/>
        <reference ref_id="CVE-2013-3334" ref_url="http://linux.oracle.com/cve/CVE-2013-3334.html" source="CVE"/>
        <reference ref_id="CVE-2013-3335" ref_url="http://linux.oracle.com/cve/CVE-2013-3335.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK &amp; Compiler before 3.7.0.1860 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325, CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331, CVE-2013-3332, CVE-2013-3333, and CVE-2013-3334.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:39.680-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:21.561-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:38.041-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23886 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:52.742-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:43.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.285-1.el6" test_ref="oval:org.mitre.oval:tst:111977"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23883" version="61" class="patch">
      <metadata>
        <title>ELSA-2014:0026: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0026-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0026.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5893" ref_url="http://linux.oracle.com/cve/CVE-2013-5893.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:36.019-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:21.244-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:37.455-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23883 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:54.176-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:42.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:112415"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:112419"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:112601"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:112479"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:112713"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23882" version="41" class="patch">
      <metadata>
        <title>ELSA-2012:1259: quagga security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>quagga</product>
        </affected>
        <reference ref_id="ELSA-2012:1259-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1259.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3323" ref_url="http://linux.oracle.com/cve/CVE-2011-3323.html" source="CVE"/>
        <reference ref_id="CVE-2011-3324" ref_url="http://linux.oracle.com/cve/CVE-2011-3324.html" source="CVE"/>
        <reference ref_id="CVE-2011-3325" ref_url="http://linux.oracle.com/cve/CVE-2011-3325.html" source="CVE"/>
        <reference ref_id="CVE-2011-3326" ref_url="http://linux.oracle.com/cve/CVE-2011-3326.html" source="CVE"/>
        <reference ref_id="CVE-2011-3327" ref_url="http://linux.oracle.com/cve/CVE-2011-3327.html" source="CVE"/>
        <reference ref_id="CVE-2012-0249" ref_url="http://linux.oracle.com/cve/CVE-2012-0249.html" source="CVE"/>
        <reference ref_id="CVE-2012-0250" ref_url="http://linux.oracle.com/cve/CVE-2012-0250.html" source="CVE"/>
        <reference ref_id="CVE-2012-0255" ref_url="http://linux.oracle.com/cve/CVE-2012-0255.html" source="CVE"/>
        <reference ref_id="CVE-2012-1820" ref_url="http://linux.oracle.com/cve/CVE-2012-1820.html" source="CVE"/>
        <description>The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:46.404-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:20.976-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:36.986-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23882 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.543-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:42.467-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="quagga-devel is earlier than 0:0.99.15-7.el6_3.2" test_ref="oval:org.mitre.oval:tst:111018"/>
          <criterion comment="quagga-contrib is earlier than 0:0.99.15-7.el6_3.2" test_ref="oval:org.mitre.oval:tst:111114"/>
          <criterion comment="quagga is earlier than 0:0.99.15-7.el6_3.2" test_ref="oval:org.mitre.oval:tst:110663"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23881" version="29" class="patch">
      <metadata>
        <title>ELSA-2012:1265: libxslt security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>libxslt</product>
        </affected>
        <reference ref_id="ELSA-2012:1265-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-1265.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1202" ref_url="http://linux.oracle.com/cve/CVE-2011-1202.html" source="CVE"/>
        <reference ref_id="CVE-2011-3970" ref_url="http://linux.oracle.com/cve/CVE-2011-3970.html" source="CVE"/>
        <reference ref_id="CVE-2012-2825" ref_url="http://linux.oracle.com/cve/CVE-2012-2825.html" source="CVE"/>
        <reference ref_id="CVE-2012-2870" ref_url="http://linux.oracle.com/cve/CVE-2012-2870.html" source="CVE"/>
        <reference ref_id="CVE-2012-2871" ref_url="http://linux.oracle.com/cve/CVE-2012-2871.html" source="CVE"/>
        <reference ref_id="CVE-2012-2893" ref_url="http://linux.oracle.com/cve/CVE-2012-2893.html" source="CVE"/>
        <description>Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:42.935-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:20.813-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:36.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23881 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.273-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:42.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:111153"/>
            <criterion comment="libxslt is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:110754"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:111136"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxslt-devel is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:110842"/>
            <criterion comment="libxslt is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:111056"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:110771"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23880" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0522: gdb security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gdb</product>
        </affected>
        <reference ref_id="ELSA-2013:0522-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0522.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4355" ref_url="http://linux.oracle.com/cve/CVE-2011-4355.html" source="CVE"/>
        <description>GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:38.914-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:20.751-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:36.566-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23880 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.557-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:42.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gdb-gdbserver is earlier than 0:7.2-60.el6" test_ref="oval:org.mitre.oval:tst:111689"/>
          <criterion comment="gdb is earlier than 0:7.2-60.el6" test_ref="oval:org.mitre.oval:tst:111648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23879" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0737: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference ref_id="ELSA-2013:0737-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0737.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1845" ref_url="http://linux.oracle.com/cve/CVE-2013-1845.html" source="CVE"/>
        <reference ref_id="CVE-2013-1846" ref_url="http://linux.oracle.com/cve/CVE-2013-1846.html" source="CVE"/>
        <reference ref_id="CVE-2013-1847" ref_url="http://linux.oracle.com/cve/CVE-2013-1847.html" source="CVE"/>
        <reference ref_id="CVE-2013-1849" ref_url="http://linux.oracle.com/cve/CVE-2013-1849.html" source="CVE"/>
        <description>The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:55.077-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:20.614-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:36.289-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23879 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.788-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:41.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111641"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111527"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111340"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111912"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111566"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111487"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111891"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111856"/>
            <criterion comment="subversion is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:111653"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111952"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111774"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111962"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111873"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111669"/>
            <criterion comment="subversion is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:111344"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23878" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0896: qemu-kvm security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2013:0896-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0896.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2007" ref_url="http://linux.oracle.com/cve/CVE-2013-2007.html" source="CVE"/>
        <description>The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:09.805-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:20.543-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:36.152-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23878 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.263-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:41.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-guest-agent-win32 is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:111914"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:111741"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:112132"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:112124"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:111943"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23877" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0156: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2013:0156-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0156.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3174" ref_url="http://linux.oracle.com/cve/CVE-2012-3174.html" source="CVE"/>
        <reference ref_id="CVE-2013-0422" ref_url="http://linux.oracle.com/cve/CVE-2013-0422.html" source="CVE"/>
        <description>Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114.  CVE-2013-0422 covers both the JMX/MBean and Reflection API issues.  NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks.  NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11.  If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:23.769-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:20.458-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:35.973-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23877 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:56.293-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:41.536-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110775"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111352"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110939"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111156"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110969"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111278"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23876" version="93" class="patch">
      <metadata>
        <title>ELSA-2013:0624: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:0624-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0624.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5085" ref_url="http://linux.oracle.com/cve/CVE-2012-5085.html" source="CVE"/>
        <reference ref_id="CVE-2013-0409" ref_url="http://linux.oracle.com/cve/CVE-2013-0409.html" source="CVE"/>
        <reference ref_id="CVE-2013-0424" ref_url="http://linux.oracle.com/cve/CVE-2013-0424.html" source="CVE"/>
        <reference ref_id="CVE-2013-0425" ref_url="http://linux.oracle.com/cve/CVE-2013-0425.html" source="CVE"/>
        <reference ref_id="CVE-2013-0426" ref_url="http://linux.oracle.com/cve/CVE-2013-0426.html" source="CVE"/>
        <reference ref_id="CVE-2013-0427" ref_url="http://linux.oracle.com/cve/CVE-2013-0427.html" source="CVE"/>
        <reference ref_id="CVE-2013-0428" ref_url="http://linux.oracle.com/cve/CVE-2013-0428.html" source="CVE"/>
        <reference ref_id="CVE-2013-0432" ref_url="http://linux.oracle.com/cve/CVE-2013-0432.html" source="CVE"/>
        <reference ref_id="CVE-2013-0433" ref_url="http://linux.oracle.com/cve/CVE-2013-0433.html" source="CVE"/>
        <reference ref_id="CVE-2013-0434" ref_url="http://linux.oracle.com/cve/CVE-2013-0434.html" source="CVE"/>
        <reference ref_id="CVE-2013-0440" ref_url="http://linux.oracle.com/cve/CVE-2013-0440.html" source="CVE"/>
        <reference ref_id="CVE-2013-0442" ref_url="http://linux.oracle.com/cve/CVE-2013-0442.html" source="CVE"/>
        <reference ref_id="CVE-2013-0443" ref_url="http://linux.oracle.com/cve/CVE-2013-0443.html" source="CVE"/>
        <reference ref_id="CVE-2013-0445" ref_url="http://linux.oracle.com/cve/CVE-2013-0445.html" source="CVE"/>
        <reference ref_id="CVE-2013-0450" ref_url="http://linux.oracle.com/cve/CVE-2013-0450.html" source="CVE"/>
        <reference ref_id="CVE-2013-0809" ref_url="http://linux.oracle.com/cve/CVE-2013-0809.html" source="CVE"/>
        <reference ref_id="CVE-2013-1476" ref_url="http://linux.oracle.com/cve/CVE-2013-1476.html" source="CVE"/>
        <reference ref_id="CVE-2013-1478" ref_url="http://linux.oracle.com/cve/CVE-2013-1478.html" source="CVE"/>
        <reference ref_id="CVE-2013-1480" ref_url="http://linux.oracle.com/cve/CVE-2013-1480.html" source="CVE"/>
        <reference ref_id="CVE-2013-1481" ref_url="http://linux.oracle.com/cve/CVE-2013-1481.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <reference ref_id="CVE-2013-1493" ref_url="http://linux.oracle.com/cve/CVE-2013-1493.html" source="CVE"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:44.475-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:20.020-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:35.093-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23876 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.696-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:40.993-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111825"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111590"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111742"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111341"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111426"/>
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111424"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23874" version="53" class="patch">
      <metadata>
        <title>ELSA-2013:0144: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0144-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0144.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0744" ref_url="http://linux.oracle.com/cve/CVE-2013-0744.html" source="CVE"/>
        <reference ref_id="CVE-2013-0746" ref_url="http://linux.oracle.com/cve/CVE-2013-0746.html" source="CVE"/>
        <reference ref_id="CVE-2013-0748" ref_url="http://linux.oracle.com/cve/CVE-2013-0748.html" source="CVE"/>
        <reference ref_id="CVE-2013-0750" ref_url="http://linux.oracle.com/cve/CVE-2013-0750.html" source="CVE"/>
        <reference ref_id="CVE-2013-0753" ref_url="http://linux.oracle.com/cve/CVE-2013-0753.html" source="CVE"/>
        <reference ref_id="CVE-2013-0754" ref_url="http://linux.oracle.com/cve/CVE-2013-0754.html" source="CVE"/>
        <reference ref_id="CVE-2013-0758" ref_url="http://linux.oracle.com/cve/CVE-2013-0758.html" source="CVE"/>
        <reference ref_id="CVE-2013-0759" ref_url="http://linux.oracle.com/cve/CVE-2013-0759.html" source="CVE"/>
        <reference ref_id="CVE-2013-0762" ref_url="http://linux.oracle.com/cve/CVE-2013-0762.html" source="CVE"/>
        <reference ref_id="CVE-2013-0766" ref_url="http://linux.oracle.com/cve/CVE-2013-0766.html" source="CVE"/>
        <reference ref_id="CVE-2013-0767" ref_url="http://linux.oracle.com/cve/CVE-2013-0767.html" source="CVE"/>
        <reference ref_id="CVE-2013-0769" ref_url="http://linux.oracle.com/cve/CVE-2013-0769.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:30.810-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:19.760-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:34.568-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23874 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.513-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:40.795-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:111305"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:110866"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:110941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:110956"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:111356"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:110858"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23873" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0571: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:0571-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0571.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4086" ref_url="http://linux.oracle.com/cve/CVE-2011-4086.html" source="CVE"/>
        <reference ref_id="CVE-2012-1601" ref_url="http://linux.oracle.com/cve/CVE-2012-1601.html" source="CVE"/>
        <description>The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after a virtual CPU already exists.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:28.474-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:19.664-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:34.380-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23873 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.029-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:40.624-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110217"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:109784"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110198"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110200"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110188"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110122"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110034"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110112"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110116"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110083"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:110008"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:109840"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23871" version="25" class="patch">
      <metadata>
        <title>ELSA-2012:1580: kernel security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1580-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1580.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2100" ref_url="http://linux.oracle.com/cve/CVE-2012-2100.html" source="CVE"/>
        <reference ref_id="CVE-2012-2375" ref_url="http://linux.oracle.com/cve/CVE-2012-2375.html" source="CVE"/>
        <reference ref_id="CVE-2012-4444" ref_url="http://linux.oracle.com/cve/CVE-2012-4444.html" source="CVE"/>
        <reference ref_id="CVE-2012-4565" ref_url="http://linux.oracle.com/cve/CVE-2012-4565.html" source="CVE"/>
        <reference ref_id="CVE-2012-5517" ref_url="http://linux.oracle.com/cve/CVE-2012-5517.html" source="CVE"/>
        <description>The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory that was hot-added by an administrator.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:12.855-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:19.512-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:34.040-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23871 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:26:00.048-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:40.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:111265"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:110592"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:110364"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:111074"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:110684"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:111157"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:110930"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:111349"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:110426"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:111283"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:110361"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:111037"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23869" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1114: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2013:1114-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1114.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4854" ref_url="http://linux.oracle.com/cve/CVE-2013-4854.html" source="CVE"/>
        <description>The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:57.001-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:19.440-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:33.924-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23869 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:52.904-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:40.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:112306"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:112052"/>
          <criterion comment="bind is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:112149"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:112244"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:112285"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:111607"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23868" version="29" class="patch">
      <metadata>
        <title>ELSA-2013:0496: Red Hat Enterprise Linux 6 kernel update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0496-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0496.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4508" ref_url="http://linux.oracle.com/cve/CVE-2012-4508.html" source="CVE"/>
        <reference ref_id="CVE-2012-4542" ref_url="http://linux.oracle.com/cve/CVE-2012-4542.html" source="CVE"/>
        <reference ref_id="CVE-2013-0190" ref_url="http://linux.oracle.com/cve/CVE-2013-0190.html" source="CVE"/>
        <reference ref_id="CVE-2013-0309" ref_url="http://linux.oracle.com/cve/CVE-2013-0309.html" source="CVE"/>
        <reference ref_id="CVE-2013-0310" ref_url="http://linux.oracle.com/cve/CVE-2013-0310.html" source="CVE"/>
        <reference ref_id="CVE-2013-0311" ref_url="http://linux.oracle.com/cve/CVE-2013-0311.html" source="CVE"/>
        <description>The translate_desc function in drivers/vhost/vhost.c in the Linux kernel before 3.7 does not properly handle cross-region descriptors, which allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:24.593-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:19.235-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:33.620-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23868 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.029-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:39.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:111301"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:111334"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:111303"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:111167"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:111445"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:111161"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:110591"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:111446"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:110964"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:111479"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:110992"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:110700"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23867" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0788: subscription-manager security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>subscription-manager</product>
        </affected>
        <reference ref_id="ELSA-2013:0788-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0788.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6137" ref_url="http://linux.oracle.com/cve/CVE-2012-6137.html" source="CVE"/>
        <description>rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:50.890-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:19.146-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:33.501-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23867 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.254-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:39.823-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:112034"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:111926"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:111981"/>
            <criterion comment="subscription-manager is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:111863"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:111850"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:112027"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:111954"/>
            <criterion comment="subscription-manager is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:112054"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23866" version="93" class="patch">
      <metadata>
        <title>ELSA-2012:1392: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2012:1392-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1392.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0547" ref_url="http://linux.oracle.com/cve/CVE-2012-0547.html" source="CVE"/>
        <reference ref_id="CVE-2012-1531" ref_url="http://linux.oracle.com/cve/CVE-2012-1531.html" source="CVE"/>
        <reference ref_id="CVE-2012-1532" ref_url="http://linux.oracle.com/cve/CVE-2012-1532.html" source="CVE"/>
        <reference ref_id="CVE-2012-1533" ref_url="http://linux.oracle.com/cve/CVE-2012-1533.html" source="CVE"/>
        <reference ref_id="CVE-2012-3143" ref_url="http://linux.oracle.com/cve/CVE-2012-3143.html" source="CVE"/>
        <reference ref_id="CVE-2012-3159" ref_url="http://linux.oracle.com/cve/CVE-2012-3159.html" source="CVE"/>
        <reference ref_id="CVE-2012-3216" ref_url="http://linux.oracle.com/cve/CVE-2012-3216.html" source="CVE"/>
        <reference ref_id="CVE-2012-4416" ref_url="http://linux.oracle.com/cve/CVE-2012-4416.html" source="CVE"/>
        <reference ref_id="CVE-2012-5068" ref_url="http://linux.oracle.com/cve/CVE-2012-5068.html" source="CVE"/>
        <reference ref_id="CVE-2012-5069" ref_url="http://linux.oracle.com/cve/CVE-2012-5069.html" source="CVE"/>
        <reference ref_id="CVE-2012-5071" ref_url="http://linux.oracle.com/cve/CVE-2012-5071.html" source="CVE"/>
        <reference ref_id="CVE-2012-5072" ref_url="http://linux.oracle.com/cve/CVE-2012-5072.html" source="CVE"/>
        <reference ref_id="CVE-2012-5073" ref_url="http://linux.oracle.com/cve/CVE-2012-5073.html" source="CVE"/>
        <reference ref_id="CVE-2012-5075" ref_url="http://linux.oracle.com/cve/CVE-2012-5075.html" source="CVE"/>
        <reference ref_id="CVE-2012-5077" ref_url="http://linux.oracle.com/cve/CVE-2012-5077.html" source="CVE"/>
        <reference ref_id="CVE-2012-5079" ref_url="http://linux.oracle.com/cve/CVE-2012-5079.html" source="CVE"/>
        <reference ref_id="CVE-2012-5081" ref_url="http://linux.oracle.com/cve/CVE-2012-5081.html" source="CVE"/>
        <reference ref_id="CVE-2012-5083" ref_url="http://linux.oracle.com/cve/CVE-2012-5083.html" source="CVE"/>
        <reference ref_id="CVE-2012-5084" ref_url="http://linux.oracle.com/cve/CVE-2012-5084.html" source="CVE"/>
        <reference ref_id="CVE-2012-5085" ref_url="http://linux.oracle.com/cve/CVE-2012-5085.html" source="CVE"/>
        <reference ref_id="CVE-2012-5086" ref_url="http://linux.oracle.com/cve/CVE-2012-5086.html" source="CVE"/>
        <reference ref_id="CVE-2012-5089" ref_url="http://linux.oracle.com/cve/CVE-2012-5089.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:03.398-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:18.678-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:32.622-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23866 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.537-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:39.240-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110725"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110572"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111274"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111106"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111240"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111134"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23865" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1326: freeradius security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>freeradius</product>
        </affected>
        <reference ref_id="ELSA-2012:1326-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1326.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3547" ref_url="http://linux.oracle.com/cve/CVE-2012-3547.html" source="CVE"/>
        <description>Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:13.435-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:18.585-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:32.485-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23865 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.387-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:39.084-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="freeradius-mysql is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:111139"/>
          <criterion comment="freeradius-perl is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:110273"/>
          <criterion comment="freeradius-unixODBC is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:111173"/>
          <criterion comment="freeradius-krb5 is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:111034"/>
          <criterion comment="freeradius-python is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:111152"/>
          <criterion comment="freeradius-utils is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:111258"/>
          <criterion comment="freeradius-ldap is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:111060"/>
          <criterion comment="freeradius-postgresql is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:111252"/>
          <criterion comment="freeradius is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:111172"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23862" version="97" class="patch">
      <metadata>
        <title>ELSA-2012:1211: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1211-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1211.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1970" ref_url="http://linux.oracle.com/cve/CVE-2012-1970.html" source="CVE"/>
        <reference ref_id="CVE-2012-1972" ref_url="http://linux.oracle.com/cve/CVE-2012-1972.html" source="CVE"/>
        <reference ref_id="CVE-2012-1973" ref_url="http://linux.oracle.com/cve/CVE-2012-1973.html" source="CVE"/>
        <reference ref_id="CVE-2012-1974" ref_url="http://linux.oracle.com/cve/CVE-2012-1974.html" source="CVE"/>
        <reference ref_id="CVE-2012-1975" ref_url="http://linux.oracle.com/cve/CVE-2012-1975.html" source="CVE"/>
        <reference ref_id="CVE-2012-1976" ref_url="http://linux.oracle.com/cve/CVE-2012-1976.html" source="CVE"/>
        <reference ref_id="CVE-2012-3956" ref_url="http://linux.oracle.com/cve/CVE-2012-3956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3957" ref_url="http://linux.oracle.com/cve/CVE-2012-3957.html" source="CVE"/>
        <reference ref_id="CVE-2012-3958" ref_url="http://linux.oracle.com/cve/CVE-2012-3958.html" source="CVE"/>
        <reference ref_id="CVE-2012-3959" ref_url="http://linux.oracle.com/cve/CVE-2012-3959.html" source="CVE"/>
        <reference ref_id="CVE-2012-3960" ref_url="http://linux.oracle.com/cve/CVE-2012-3960.html" source="CVE"/>
        <reference ref_id="CVE-2012-3961" ref_url="http://linux.oracle.com/cve/CVE-2012-3961.html" source="CVE"/>
        <reference ref_id="CVE-2012-3962" ref_url="http://linux.oracle.com/cve/CVE-2012-3962.html" source="CVE"/>
        <reference ref_id="CVE-2012-3963" ref_url="http://linux.oracle.com/cve/CVE-2012-3963.html" source="CVE"/>
        <reference ref_id="CVE-2012-3964" ref_url="http://linux.oracle.com/cve/CVE-2012-3964.html" source="CVE"/>
        <reference ref_id="CVE-2012-3966" ref_url="http://linux.oracle.com/cve/CVE-2012-3966.html" source="CVE"/>
        <reference ref_id="CVE-2012-3967" ref_url="http://linux.oracle.com/cve/CVE-2012-3967.html" source="CVE"/>
        <reference ref_id="CVE-2012-3968" ref_url="http://linux.oracle.com/cve/CVE-2012-3968.html" source="CVE"/>
        <reference ref_id="CVE-2012-3969" ref_url="http://linux.oracle.com/cve/CVE-2012-3969.html" source="CVE"/>
        <reference ref_id="CVE-2012-3970" ref_url="http://linux.oracle.com/cve/CVE-2012-3970.html" source="CVE"/>
        <reference ref_id="CVE-2012-3972" ref_url="http://linux.oracle.com/cve/CVE-2012-3972.html" source="CVE"/>
        <reference ref_id="CVE-2012-3978" ref_url="http://linux.oracle.com/cve/CVE-2012-3978.html" source="CVE"/>
        <reference ref_id="CVE-2012-3980" ref_url="http://linux.oracle.com/cve/CVE-2012-3980.html" source="CVE"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:34.186-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:18.141-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:31.301-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23862 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.358-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:38.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:110681"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:110922"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23861" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0523: ccid security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ccid</product>
        </affected>
        <reference ref_id="ELSA-2013:0523-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0523.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4530" ref_url="http://linux.oracle.com/cve/CVE-2010-4530.html" source="CVE"/>
        <description>Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow.  NOTE: some sources refer to this issue as an integer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:43.212-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:18.078-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:31.204-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23861 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.352-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:38.358-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="ccid is earlier than 0:1.3.9-6.el6" test_ref="oval:org.mitre.oval:tst:111532"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23860" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1081: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference ref_id="ELSA-2012:1081-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1081.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2337" ref_url="http://linux.oracle.com/cve/CVE-2012-2337.html" source="CVE"/>
        <description>sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:40.847-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:17.995-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:31.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23860 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:55.144-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:38.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8" test_ref="oval:org.mitre.oval:tst:110692"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="sudo is earlier than 0:1.7.4p5-12.el6_3" test_ref="oval:org.mitre.oval:tst:110408"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23859" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:0059: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2012:0059-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0059.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4108" ref_url="http://linux.oracle.com/cve/CVE-2011-4108.html" source="CVE"/>
        <reference ref_id="CVE-2011-4576" ref_url="http://linux.oracle.com/cve/CVE-2011-4576.html" source="CVE"/>
        <reference ref_id="CVE-2011-4577" ref_url="http://linux.oracle.com/cve/CVE-2011-4577.html" source="CVE"/>
        <reference ref_id="CVE-2011-4619" ref_url="http://linux.oracle.com/cve/CVE-2011-4619.html" source="CVE"/>
        <description>The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:05.940-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:17.864-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:30.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23859 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:56.083-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:38.101-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:109859"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:109882"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:109531"/>
          <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:109828"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23858" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1100: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2013:1100-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1100.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2231" ref_url="http://linux.oracle.com/cve/CVE-2013-2231.html" source="CVE"/>
        <description>Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, and Workstation Supplementary 6, when installing on Windows, allows local users to gain privileges via a crafted program in an unspecified folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:12.721-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:17.769-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:30.735-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23858 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.156-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:38.003-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:112209"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:112310"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:112074"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:112000"/>
          <criterion comment="qemu-guest-agent-win32 is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:112019"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23856" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1283: openjpeg security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openjpeg</product>
        </affected>
        <reference ref_id="ELSA-2012:1283-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1283.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3535" ref_url="http://linux.oracle.com/cve/CVE-2012-3535.html" source="CVE"/>
        <description>Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted JPEG2000 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:10.925-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:17.588-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:30.505-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23856 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:54.340-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:37.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openjpeg-libs is earlier than 0:1.3-9.el6_3" test_ref="oval:org.mitre.oval:tst:110898"/>
          <criterion comment="openjpeg is earlier than 0:1.3-9.el6_3" test_ref="oval:org.mitre.oval:tst:111102"/>
          <criterion comment="openjpeg-devel is earlier than 0:1.3-9.el6_3" test_ref="oval:org.mitre.oval:tst:110966"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23855" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1806: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2013:1806-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1806.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4408" ref_url="http://linux.oracle.com/cve/CVE-2013-4408.html" source="CVE"/>
        <reference ref_id="CVE-2013-4475" ref_url="http://linux.oracle.com/cve/CVE-2013-4475.html" source="CVE"/>
        <description>Samba 3.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:17.238-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:17.362-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:30.332-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23855 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:56.431-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:37.740-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112434"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112578"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112650"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:111735"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112487"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112371"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112191"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:112423"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-common is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112468"/>
            <criterion comment="samba is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112630"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112573"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112418"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112117"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:111713"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112394"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112707"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112706"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112647"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112662"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:112546"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23854" version="29" class="patch">
      <metadata>
        <title>ELSA-2012:0144: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:0144-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0144.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0752" ref_url="http://linux.oracle.com/cve/CVE-2012-0752.html" source="CVE"/>
        <reference ref_id="CVE-2012-0753" ref_url="http://linux.oracle.com/cve/CVE-2012-0753.html" source="CVE"/>
        <reference ref_id="CVE-2012-0754" ref_url="http://linux.oracle.com/cve/CVE-2012-0754.html" source="CVE"/>
        <reference ref_id="CVE-2012-0755" ref_url="http://linux.oracle.com/cve/CVE-2012-0755.html" source="CVE"/>
        <reference ref_id="CVE-2012-0756" ref_url="http://linux.oracle.com/cve/CVE-2012-0756.html" source="CVE"/>
        <reference ref_id="CVE-2012-0767" ref_url="http://linux.oracle.com/cve/CVE-2012-0767.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:01.579-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:17.169-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:30.044-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23854 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.959-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:37.498-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:10.3.183.15-1.el6" test_ref="oval:org.mitre.oval:tst:109714"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23853" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0393: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2012:0393-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0393.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0864" ref_url="http://linux.oracle.com/cve/CVE-2012-0864.html" source="CVE"/>
        <description>Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:20.671-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:17.014-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:29.907-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23853 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:56.565-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:37.403-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="glibc-devel is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:109564"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:109670"/>
          <criterion comment="glibc is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:109879"/>
          <criterion comment="nscd is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:110153"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:109780"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:109770"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:109890"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23852" version="65" class="patch">
      <metadata>
        <title>ELSA-2013:0772: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2013:0772-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0772.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5614" ref_url="http://linux.oracle.com/cve/CVE-2012-5614.html" source="CVE"/>
        <reference ref_id="CVE-2013-1506" ref_url="http://linux.oracle.com/cve/CVE-2013-1506.html" source="CVE"/>
        <reference ref_id="CVE-2013-1521" ref_url="http://linux.oracle.com/cve/CVE-2013-1521.html" source="CVE"/>
        <reference ref_id="CVE-2013-1531" ref_url="http://linux.oracle.com/cve/CVE-2013-1531.html" source="CVE"/>
        <reference ref_id="CVE-2013-1532" ref_url="http://linux.oracle.com/cve/CVE-2013-1532.html" source="CVE"/>
        <reference ref_id="CVE-2013-1544" ref_url="http://linux.oracle.com/cve/CVE-2013-1544.html" source="CVE"/>
        <reference ref_id="CVE-2013-1548" ref_url="http://linux.oracle.com/cve/CVE-2013-1548.html" source="CVE"/>
        <reference ref_id="CVE-2013-1552" ref_url="http://linux.oracle.com/cve/CVE-2013-1552.html" source="CVE"/>
        <reference ref_id="CVE-2013-1555" ref_url="http://linux.oracle.com/cve/CVE-2013-1555.html" source="CVE"/>
        <reference ref_id="CVE-2013-2375" ref_url="http://linux.oracle.com/cve/CVE-2013-2375.html" source="CVE"/>
        <reference ref_id="CVE-2013-2378" ref_url="http://linux.oracle.com/cve/CVE-2013-2378.html" source="CVE"/>
        <reference ref_id="CVE-2013-2389" ref_url="http://linux.oracle.com/cve/CVE-2013-2389.html" source="CVE"/>
        <reference ref_id="CVE-2013-2391" ref_url="http://linux.oracle.com/cve/CVE-2013-2391.html" source="CVE"/>
        <reference ref_id="CVE-2013-2392" ref_url="http://linux.oracle.com/cve/CVE-2013-2392.html" source="CVE"/>
        <reference ref_id="CVE-2013-3808" ref_url="http://linux.oracle.com/cve/CVE-2013-3808.html" source="CVE"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:39.140-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:16.489-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:29.223-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23852 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.894-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:37.004-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-bench is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:112041"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:112015"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:111780"/>
          <criterion comment="mysql is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:111552"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:111257"/>
          <criterion comment="mysql-server is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:112046"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:111433"/>
          <criterion comment="mysql-test is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:112029"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23849" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0140: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0140-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0140.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3026" ref_url="http://linux.oracle.com/cve/CVE-2011-3026.html" source="CVE"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:11.331-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:16.325-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:29.104-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23849 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:57.663-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:36.824-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.18-2.el6_2" test_ref="oval:org.mitre.oval:tst:109655"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23847" version="53" class="patch">
      <metadata>
        <title>ELSA-2013:0145: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0145-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0145.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0744" ref_url="http://linux.oracle.com/cve/CVE-2013-0744.html" source="CVE"/>
        <reference ref_id="CVE-2013-0746" ref_url="http://linux.oracle.com/cve/CVE-2013-0746.html" source="CVE"/>
        <reference ref_id="CVE-2013-0748" ref_url="http://linux.oracle.com/cve/CVE-2013-0748.html" source="CVE"/>
        <reference ref_id="CVE-2013-0750" ref_url="http://linux.oracle.com/cve/CVE-2013-0750.html" source="CVE"/>
        <reference ref_id="CVE-2013-0753" ref_url="http://linux.oracle.com/cve/CVE-2013-0753.html" source="CVE"/>
        <reference ref_id="CVE-2013-0754" ref_url="http://linux.oracle.com/cve/CVE-2013-0754.html" source="CVE"/>
        <reference ref_id="CVE-2013-0758" ref_url="http://linux.oracle.com/cve/CVE-2013-0758.html" source="CVE"/>
        <reference ref_id="CVE-2013-0759" ref_url="http://linux.oracle.com/cve/CVE-2013-0759.html" source="CVE"/>
        <reference ref_id="CVE-2013-0762" ref_url="http://linux.oracle.com/cve/CVE-2013-0762.html" source="CVE"/>
        <reference ref_id="CVE-2013-0766" ref_url="http://linux.oracle.com/cve/CVE-2013-0766.html" source="CVE"/>
        <reference ref_id="CVE-2013-0767" ref_url="http://linux.oracle.com/cve/CVE-2013-0767.html" source="CVE"/>
        <reference ref_id="CVE-2013-0769" ref_url="http://linux.oracle.com/cve/CVE-2013-0769.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:20.443-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:15.836-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:28.508-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23847 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.058-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:36.467-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el6_3" test_ref="oval:org.mitre.oval:tst:111316"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el5_9" test_ref="oval:org.mitre.oval:tst:111201"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23846" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0643: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:0643-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0643.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0646" ref_url="http://linux.oracle.com/cve/CVE-2013-0646.html" source="CVE"/>
        <reference ref_id="CVE-2013-0650" ref_url="http://linux.oracle.com/cve/CVE-2013-0650.html" source="CVE"/>
        <reference ref_id="CVE-2013-1371" ref_url="http://linux.oracle.com/cve/CVE-2013-1371.html" source="CVE"/>
        <reference ref_id="CVE-2013-1375" ref_url="http://linux.oracle.com/cve/CVE-2013-1375.html" source="CVE"/>
        <description>Heap-based buffer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK &amp; Compiler before 3.6.0.6090 allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:44.107-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:15.679-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:28.290-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23846 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:54.553-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:36.325-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.275-2.el6" test_ref="oval:org.mitre.oval:tst:111722"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23845" version="5" class="patch">
      <metadata>
        <title>ELSA-2014:0420: qemu-kvm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2014:0420-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0420.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0142" ref_url="http://linux.oracle.com/cve/CVE-2014-0142.html" source="CVE"/>
        <reference ref_id="CVE-2014-0143" ref_url="http://linux.oracle.com/cve/CVE-2014-0143.html" source="CVE"/>
        <reference ref_id="CVE-2014-0144" ref_url="http://linux.oracle.com/cve/CVE-2014-0144.html" source="CVE"/>
        <reference ref_id="CVE-2014-0145" ref_url="http://linux.oracle.com/cve/CVE-2014-0145.html" source="CVE"/>
        <reference ref_id="CVE-2014-0146" ref_url="http://linux.oracle.com/cve/CVE-2014-0146.html" source="CVE"/>
        <reference ref_id="CVE-2014-0147" ref_url="http://linux.oracle.com/cve/CVE-2014-0147.html" source="CVE"/>
        <reference ref_id="CVE-2014-0148" ref_url="http://linux.oracle.com/cve/CVE-2014-0148.html" source="CVE"/>
        <reference ref_id="CVE-2014-0150" ref_url="http://linux.oracle.com/cve/CVE-2014-0150.html" source="CVE"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.
Multiple integer overflow, input validation, logic error, and buffer
overflow flaws were discovered in various QEMU block drivers. An attacker
able to modify a disk image file loaded by a guest could use these flaws to
crash the guest, or corrupt QEMU process memory on the host, potentially
resulting in arbitrary code execution on the host with the privileges of
the QEMU process. (CVE-2014-0143, CVE-2014-0144, CVE-2014-0145,
CVE-2014-0147)
A buffer overflow flaw was found in the way the virtio_net_handle_mac()
function of QEMU processed guest requests to update the table of MAC
addresses. A privileged guest user could use this flaw to corrupt QEMU
process memory on the host, potentially resulting in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2014-0150)
A divide-by-zero flaw was found in the seek_to_sector() function of the
parallels block driver in QEMU. An attacker able to modify a disk image
file loaded by a guest could use this flaw to crash the guest.
(CVE-2014-0142)
A NULL pointer dereference flaw was found in the QCOW2 block driver in
QEMU. An attacker able to modify a disk image file loaded by a guest could
use this flaw to crash the guest. (CVE-2014-0146)
It was found that the block driver for Hyper-V VHDX images did not
correctly calculate BAT (Block Allocation Table) entries due to a missing
bounds check. An attacker able to modify a disk image file loaded by a
guest could use this flaw to crash the guest. (CVE-2014-0148)
The CVE-2014-0143 issues were discovered by Kevin Wolf and Stefan Hajnoczi
of Red Hat, the CVE-2014-0144 issues were discovered by Fam Zheng, Jeff
Cody, Kevin Wolf, and Stefan Hajnoczi of Red Hat, the CVE-2014-0145 issues
were discovered by Stefan Hajnoczi of Red Hat, the CVE-2014-0150 issue was
discovered by Michael S. Tsirkin of Red Hat, the CVE-2014-0142,
CVE-2014-0146, and CVE-2014-0147 issues were discovered by Kevin Wolf of
Red Hat, and the CVE-2014-0148 issue was discovered by Jeff Cody of
Red Hat.
All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:36.903-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:20.178-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:56.081-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23845 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:28.160-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:02.411-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:113787"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:114318"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:113530"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:114084"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23844" version="57" class="patch">
      <metadata>
        <title>ELSA-2012:1019: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2012:1019-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1019.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0551" ref_url="http://linux.oracle.com/cve/CVE-2012-0551.html" source="CVE"/>
        <reference ref_id="CVE-2012-1711" ref_url="http://linux.oracle.com/cve/CVE-2012-1711.html" source="CVE"/>
        <reference ref_id="CVE-2012-1713" ref_url="http://linux.oracle.com/cve/CVE-2012-1713.html" source="CVE"/>
        <reference ref_id="CVE-2012-1716" ref_url="http://linux.oracle.com/cve/CVE-2012-1716.html" source="CVE"/>
        <reference ref_id="CVE-2012-1717" ref_url="http://linux.oracle.com/cve/CVE-2012-1717.html" source="CVE"/>
        <reference ref_id="CVE-2012-1718" ref_url="http://linux.oracle.com/cve/CVE-2012-1718.html" source="CVE"/>
        <reference ref_id="CVE-2012-1719" ref_url="http://linux.oracle.com/cve/CVE-2012-1719.html" source="CVE"/>
        <reference ref_id="CVE-2012-1721" ref_url="http://linux.oracle.com/cve/CVE-2012-1721.html" source="CVE"/>
        <reference ref_id="CVE-2012-1722" ref_url="http://linux.oracle.com/cve/CVE-2012-1722.html" source="CVE"/>
        <reference ref_id="CVE-2012-1723" ref_url="http://linux.oracle.com/cve/CVE-2012-1723.html" source="CVE"/>
        <reference ref_id="CVE-2012-1724" ref_url="http://linux.oracle.com/cve/CVE-2012-1724.html" source="CVE"/>
        <reference ref_id="CVE-2012-1725" ref_url="http://linux.oracle.com/cve/CVE-2012-1725.html" source="CVE"/>
        <reference ref_id="CVE-2012-1726" ref_url="http://linux.oracle.com/cve/CVE-2012-1726.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:51.773-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:15.303-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:27.725-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23844 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:53.752-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:36.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:110155"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:110240"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:110388"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:110289"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:110317"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23843" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0683: bind-dyndb-ldap security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind-dyndb-ldap</product>
        </affected>
        <reference ref_id="ELSA-2012:0683-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0683.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2134" ref_url="http://linux.oracle.com/cve/CVE-2012-2134.html" source="CVE"/>
        <description>The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap before 1.1.0rc1 does not properly handle LDAP query errors, which allows remote attackers to cause a denial of service (infinite loop and named server hang) via a non-alphabet character in the base DN in an LDAP search DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:33.981-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:15.223-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:27.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23843 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:52.381-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:36.082-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="bind-dyndb-ldap is earlier than 0:0.2.0-7.el6_2.1" test_ref="oval:org.mitre.oval:tst:110313"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23841" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1037: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:1037-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1037.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2143" ref_url="http://linux.oracle.com/cve/CVE-2012-2143.html" source="CVE"/>
        <reference ref_id="CVE-2012-2655" ref_url="http://linux.oracle.com/cve/CVE-2012-2655.html" source="CVE"/>
        <description>PostgreSQL 8.3.x before 8.3.19, 8.4.x before 8.4.12, 9.0.x before 9.0.8, and 9.1.x before 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:38.652-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:15.090-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:27.352-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23841 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.914-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:35.920-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-server is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110568"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110629"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110509"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110621"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110616"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110303"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110468"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110630"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110507"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110560"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110617"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:110387"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110545"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110554"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110623"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110201"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110486"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110581"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110372"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:109699"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:109991"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:110634"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23840" version="65" class="patch">
      <metadata>
        <title>ELSA-2012:0509: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference ref_id="ELSA-2012:0509-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0509.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1143" ref_url="http://linux.oracle.com/cve/CVE-2011-1143.html" source="CVE"/>
        <reference ref_id="CVE-2011-1590" ref_url="http://linux.oracle.com/cve/CVE-2011-1590.html" source="CVE"/>
        <reference ref_id="CVE-2011-1957" ref_url="http://linux.oracle.com/cve/CVE-2011-1957.html" source="CVE"/>
        <reference ref_id="CVE-2011-1958" ref_url="http://linux.oracle.com/cve/CVE-2011-1958.html" source="CVE"/>
        <reference ref_id="CVE-2011-1959" ref_url="http://linux.oracle.com/cve/CVE-2011-1959.html" source="CVE"/>
        <reference ref_id="CVE-2011-2174" ref_url="http://linux.oracle.com/cve/CVE-2011-2174.html" source="CVE"/>
        <reference ref_id="CVE-2011-2175" ref_url="http://linux.oracle.com/cve/CVE-2011-2175.html" source="CVE"/>
        <reference ref_id="CVE-2011-2597" ref_url="http://linux.oracle.com/cve/CVE-2011-2597.html" source="CVE"/>
        <reference ref_id="CVE-2011-2698" ref_url="http://linux.oracle.com/cve/CVE-2011-2698.html" source="CVE"/>
        <reference ref_id="CVE-2011-4102" ref_url="http://linux.oracle.com/cve/CVE-2011-4102.html" source="CVE"/>
        <reference ref_id="CVE-2012-0041" ref_url="http://linux.oracle.com/cve/CVE-2012-0041.html" source="CVE"/>
        <reference ref_id="CVE-2012-0042" ref_url="http://linux.oracle.com/cve/CVE-2012-0042.html" source="CVE"/>
        <reference ref_id="CVE-2012-0066" ref_url="http://linux.oracle.com/cve/CVE-2012-0066.html" source="CVE"/>
        <reference ref_id="CVE-2012-0067" ref_url="http://linux.oracle.com/cve/CVE-2012-0067.html" source="CVE"/>
        <reference ref_id="CVE-2012-1595" ref_url="http://linux.oracle.com/cve/CVE-2012-1595.html" source="CVE"/>
        <description>The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:21.214-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:14.725-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:26.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23840 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.148-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:35.498-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="wireshark is earlier than 0:1.2.15-2.el6_2.1" test_ref="oval:org.mitre.oval:tst:109810"/>
          <criterion comment="wireshark-devel is earlier than 0:1.2.15-2.el6_2.1" test_ref="oval:org.mitre.oval:tst:110165"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.2.15-2.el6_2.1" test_ref="oval:org.mitre.oval:tst:110056"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23839" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0050: qemu-kvm security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2012:0050-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0050.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0029" ref_url="http://linux.oracle.com/cve/CVE-2012-0029.html" source="CVE"/>
        <description>Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:14.394-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:14.653-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:26.637-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23839 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.773-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:35.397-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.209.el6_2.4" test_ref="oval:org.mitre.oval:tst:109924"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.209.el6_2.4" test_ref="oval:org.mitre.oval:tst:109774"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.209.el6_2.4" test_ref="oval:org.mitre.oval:tst:109619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23838" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:1778: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference ref_id="ELSA-2013:1778-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1778.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5576" ref_url="http://linux.oracle.com/cve/CVE-2012-5576.html" source="CVE"/>
        <reference ref_id="CVE-2013-1913" ref_url="http://linux.oracle.com/cve/CVE-2013-1913.html" source="CVE"/>
        <reference ref_id="CVE-2013-1978" ref_url="http://linux.oracle.com/cve/CVE-2013-1978.html" source="CVE"/>
        <description>Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:16.585-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:14.521-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:26.448-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23838 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.661-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:35.244-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gimp-libs is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:111598"/>
            <criterion comment="gimp-devel is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:112330"/>
            <criterion comment="gimp is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:112531"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gimp-libs is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:112435"/>
            <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:112451"/>
            <criterion comment="gimp-devel is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:112413"/>
            <criterion comment="gimp is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:111649"/>
            <criterion comment="gimp-help-browser is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:112498"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23837" version="5" class="patch">
      <metadata>
        <title>ELSA-2013:0213: nss, nss-util, and nspr security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
          <product>nspr</product>
        </affected>
        <reference ref_id="ELSA-2013:0213-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0213.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.
It was found that a Certificate Authority (CA) mis-issued two intermediate
certificates to customers. These certificates could be used to launch
man-in-the-middle attacks. This update renders those certificates as
untrusted. This covers all uses of the certificates, including SSL, S/MIME,
and code signing. (BZ#890605)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
In addition, the nss package has been upgraded to upstream version 3.13.6,
the nss-util package has been upgraded to upstream version 3.13.6, and the
nspr package has been upgraded to upstream version 4.9.2. These updates
provide a number of bug fixes and enhancements over the previous versions.
(BZ#891663, BZ#891670, BZ#891661)
Users of NSS, NSPR, and nss-util are advised to upgrade to these updated
packages, which fix these issues and add these enhancements. After
installing this update, applications using NSS, NSPR, or nss-util must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:24.209-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:14.455-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:26.356-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23837 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:56.897-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:35.160-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nss-util is earlier than 0:3.13.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:110670"/>
          <criterion comment="nss-util-devel is earlier than 0:3.13.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:111292"/>
          <criterion comment="nss-tools is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:110901"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:110534"/>
          <criterion comment="nss-sysinit is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:111311"/>
          <criterion comment="nss is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:111261"/>
          <criterion comment="nss-devel is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:110428"/>
          <criterion comment="nspr is earlier than 0:4.9.2-0.el6_3.1" test_ref="oval:org.mitre.oval:tst:110927"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.2-0.el6_3.1" test_ref="oval:org.mitre.oval:tst:110972"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23836" version="25" class="patch">
      <metadata>
        <title>ELSA-2012:0128: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2012:0128-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0128.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3607" ref_url="http://linux.oracle.com/cve/CVE-2011-3607.html" source="CVE"/>
        <reference ref_id="CVE-2011-3639" ref_url="http://linux.oracle.com/cve/CVE-2011-3639.html" source="CVE"/>
        <reference ref_id="CVE-2011-4317" ref_url="http://linux.oracle.com/cve/CVE-2011-4317.html" source="CVE"/>
        <reference ref_id="CVE-2012-0031" ref_url="http://linux.oracle.com/cve/CVE-2012-0031.html" source="CVE"/>
        <reference ref_id="CVE-2012-0053" ref_url="http://linux.oracle.com/cve/CVE-2012-0053.html" source="CVE"/>
        <description>protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:10.717-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:14.175-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:26.073-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23836 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.756-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:34.913-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="httpd-devel is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:109578"/>
          <criterion comment="httpd-tools is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:110067"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:110046"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:110001"/>
          <criterion comment="httpd is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:109434"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23834" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1268: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:1268-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1268.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4244" ref_url="http://linux.oracle.com/cve/CVE-2012-4244.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:49.218-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:13.907-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:25.821-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23834 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:59.648-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:34.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110993"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110920"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:111123"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110285"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110936"/>
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:110770"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23832" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:0223: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0223-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0223.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4398" ref_url="http://linux.oracle.com/cve/CVE-2012-4398.html" source="CVE"/>
        <reference ref_id="CVE-2012-4461" ref_url="http://linux.oracle.com/cve/CVE-2012-4461.html" source="CVE"/>
        <reference ref_id="CVE-2012-4530" ref_url="http://linux.oracle.com/cve/CVE-2012-4530.html" source="CVE"/>
        <description>The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:25.925-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:13.672-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:25.607-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23832 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:58.455-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:34.651-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:111360"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:111350"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:110562"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:110788"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:111302"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:111117"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:111428"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:111411"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:111269"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:110610"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:111087"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:111355"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23831" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0748: libvirt security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2012:0748-05" ref_url="http://linux.oracle.com/errata/ELSA-2012-0748.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2693" ref_url="http://linux.oracle.com/cve/CVE-2012-2693.html" source="CVE"/>
        <description>libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:23.421-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:13.574-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:25.493-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23831 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:53.030-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:34.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:110350"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:110472"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:110314"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:110455"/>
          <criterion comment="libvirt is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:110510"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23828" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0410: raptor security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>raptor</product>
        </affected>
        <reference ref_id="ELSA-2012:0410-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0410.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0037" ref_url="http://linux.oracle.com/cve/CVE-2012-0037.html" source="CVE"/>
        <description>Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:06.872-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:13.299-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:25.320-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23828 - optimisation of Oracle Linux content" date="2014-05-05T17:23:00.551-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:25:56.193-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:34.376-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="raptor-devel is earlier than 0:1.4.18-5.el6_2.1" test_ref="oval:org.mitre.oval:tst:110043"/>
          <criterion comment="raptor is earlier than 0:1.4.18-5.el6_2.1" test_ref="oval:org.mitre.oval:tst:110100"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23826" version="45" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0715: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0715-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0715.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3101" ref_url="http://linux.oracle.com/cve/CVE-2011-3101.html" source="CVE"/>
        <reference ref_id="CVE-2012-1937" ref_url="http://linux.oracle.com/cve/CVE-2012-1937.html" source="CVE"/>
        <reference ref_id="CVE-2012-1938" ref_url="http://linux.oracle.com/cve/CVE-2012-1938.html" source="CVE"/>
        <reference ref_id="CVE-2012-1939" ref_url="http://linux.oracle.com/cve/CVE-2012-1939.html" source="CVE"/>
        <reference ref_id="CVE-2012-1940" ref_url="http://linux.oracle.com/cve/CVE-2012-1940.html" source="CVE"/>
        <reference ref_id="CVE-2012-1941" ref_url="http://linux.oracle.com/cve/CVE-2012-1941.html" source="CVE"/>
        <reference ref_id="CVE-2012-1944" ref_url="http://linux.oracle.com/cve/CVE-2012-1944.html" source="CVE"/>
        <reference ref_id="CVE-2012-1945" ref_url="http://linux.oracle.com/cve/CVE-2012-1945.html" source="CVE"/>
        <reference ref_id="CVE-2012-1946" ref_url="http://linux.oracle.com/cve/CVE-2012-1946.html" source="CVE"/>
        <reference ref_id="CVE-2012-1947" ref_url="http://linux.oracle.com/cve/CVE-2012-1947.html" source="CVE"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:29.383-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:12.940-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:24.891-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23826 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:34.479-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:56:32.614-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:56:32.614-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el5_8" test_ref="oval:org.mitre.oval:tst:110394"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el6_2" test_ref="oval:org.mitre.oval:tst:110019"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23824" version="29" class="patch">
      <metadata>
        <title>ELSA-2012:1245: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2012:1245-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1245.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1713" ref_url="http://linux.oracle.com/cve/CVE-2012-1713.html" source="CVE"/>
        <reference ref_id="CVE-2012-1716" ref_url="http://linux.oracle.com/cve/CVE-2012-1716.html" source="CVE"/>
        <reference ref_id="CVE-2012-1717" ref_url="http://linux.oracle.com/cve/CVE-2012-1717.html" source="CVE"/>
        <reference ref_id="CVE-2012-1718" ref_url="http://linux.oracle.com/cve/CVE-2012-1718.html" source="CVE"/>
        <reference ref_id="CVE-2012-1719" ref_url="http://linux.oracle.com/cve/CVE-2012-1719.html" source="CVE"/>
        <reference ref_id="CVE-2012-1725" ref_url="http://linux.oracle.com/cve/CVE-2012-1725.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:38.907-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:12.304-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:24.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23824 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:51.075-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:34.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110902"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110727"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110539"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111092"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111112"/>
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111111"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110666"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23823" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0612: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2013:0612-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0612.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4481" ref_url="http://linux.oracle.com/cve/CVE-2012-4481.html" source="CVE"/>
        <reference ref_id="CVE-2013-1821" ref_url="http://linux.oracle.com/cve/CVE-2013-1821.html" source="CVE"/>
        <description>lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:36.805-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:11.978-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:24.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23823 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:55.315-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:34.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ruby is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:111729"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:111064"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:111756"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:111721"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:111236"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:111782"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:111393"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:111773"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:111626"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23822" version="45" class="patch">
      <metadata>
        <title>ELSA-2013:0981: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0981-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0981.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1682" ref_url="http://linux.oracle.com/cve/CVE-2013-1682.html" source="CVE"/>
        <reference ref_id="CVE-2013-1684" ref_url="http://linux.oracle.com/cve/CVE-2013-1684.html" source="CVE"/>
        <reference ref_id="CVE-2013-1685" ref_url="http://linux.oracle.com/cve/CVE-2013-1685.html" source="CVE"/>
        <reference ref_id="CVE-2013-1686" ref_url="http://linux.oracle.com/cve/CVE-2013-1686.html" source="CVE"/>
        <reference ref_id="CVE-2013-1687" ref_url="http://linux.oracle.com/cve/CVE-2013-1687.html" source="CVE"/>
        <reference ref_id="CVE-2013-1690" ref_url="http://linux.oracle.com/cve/CVE-2013-1690.html" source="CVE"/>
        <reference ref_id="CVE-2013-1692" ref_url="http://linux.oracle.com/cve/CVE-2013-1692.html" source="CVE"/>
        <reference ref_id="CVE-2013-1693" ref_url="http://linux.oracle.com/cve/CVE-2013-1693.html" source="CVE"/>
        <reference ref_id="CVE-2013-1694" ref_url="http://linux.oracle.com/cve/CVE-2013-1694.html" source="CVE"/>
        <reference ref_id="CVE-2013-1697" ref_url="http://linux.oracle.com/cve/CVE-2013-1697.html" source="CVE"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:09.982-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:11.680-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:23.916-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23822 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:47.988-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:112067"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:111978"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:111703"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:112213"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:112107"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:111905"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23820" version="69" class="patch">
      <metadata>
        <title>ELSA-2012:1482: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1482-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1482.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4201" ref_url="http://linux.oracle.com/cve/CVE-2012-4201.html" source="CVE"/>
        <reference ref_id="CVE-2012-4202" ref_url="http://linux.oracle.com/cve/CVE-2012-4202.html" source="CVE"/>
        <reference ref_id="CVE-2012-4207" ref_url="http://linux.oracle.com/cve/CVE-2012-4207.html" source="CVE"/>
        <reference ref_id="CVE-2012-4209" ref_url="http://linux.oracle.com/cve/CVE-2012-4209.html" source="CVE"/>
        <reference ref_id="CVE-2012-4210" ref_url="http://linux.oracle.com/cve/CVE-2012-4210.html" source="CVE"/>
        <reference ref_id="CVE-2012-4214" ref_url="http://linux.oracle.com/cve/CVE-2012-4214.html" source="CVE"/>
        <reference ref_id="CVE-2012-4215" ref_url="http://linux.oracle.com/cve/CVE-2012-4215.html" source="CVE"/>
        <reference ref_id="CVE-2012-4216" ref_url="http://linux.oracle.com/cve/CVE-2012-4216.html" source="CVE"/>
        <reference ref_id="CVE-2012-5829" ref_url="http://linux.oracle.com/cve/CVE-2012-5829.html" source="CVE"/>
        <reference ref_id="CVE-2012-5830" ref_url="http://linux.oracle.com/cve/CVE-2012-5830.html" source="CVE"/>
        <reference ref_id="CVE-2012-5833" ref_url="http://linux.oracle.com/cve/CVE-2012-5833.html" source="CVE"/>
        <reference ref_id="CVE-2012-5835" ref_url="http://linux.oracle.com/cve/CVE-2012-5835.html" source="CVE"/>
        <reference ref_id="CVE-2012-5839" ref_url="http://linux.oracle.com/cve/CVE-2012-5839.html" source="CVE"/>
        <reference ref_id="CVE-2012-5840" ref_url="http://linux.oracle.com/cve/CVE-2012-5840.html" source="CVE"/>
        <reference ref_id="CVE-2012-5841" ref_url="http://linux.oracle.com/cve/CVE-2012-5841.html" source="CVE"/>
        <reference ref_id="CVE-2012-5842" ref_url="http://linux.oracle.com/cve/CVE-2012-5842.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:39:59.673-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.992-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:23.086-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23820 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:55.681-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.425-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110649"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110953"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:111108"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:111195"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:111217"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:111183"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23819" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0276: libvirt security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2013:0276-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0276.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3411" ref_url="http://linux.oracle.com/cve/CVE-2012-3411.html" source="CVE"/>
        <description>Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:30.573-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.856-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:22.979-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23819 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:49.703-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.327-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:111495"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:111507"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:111460"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:111198"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:111366"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23818" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0216: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2013:0216-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0216.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5669" ref_url="http://linux.oracle.com/cve/CVE-2012-5669.html" source="CVE"/>
        <description>The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:23.342-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.746-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:22.856-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23818 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.318-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:111325"/>
            <criterion comment="freetype is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:111169"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:111219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:110710"/>
            <criterion comment="freetype is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:111390"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:111361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23816" version="5" class="patch">
      <metadata>
        <title>ELSA-2013:1861: nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2013:1861-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1861.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.
It was found that a subordinate Certificate Authority (CA) mis-issued an
intermediate certificate, which could be used to conduct man-in-the-middle
attacks. This update renders that particular intermediate certificate as
untrusted. (BZ#1038894)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:01.321-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.678-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:22.765-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23816 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.780-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:112771"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:112600"/>
            <criterion comment="nss is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:112710"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:112558"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112464"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112182"/>
            <criterion comment="nss-sysinit is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112735"/>
            <criterion comment="nss is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112375"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:112538"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23815" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0628: 389-ds-base security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference ref_id="ELSA-2013:0628-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0628.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0312" ref_url="http://linux.oracle.com/cve/CVE-2013-0312.html" source="CVE"/>
        <description>389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:41.481-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.590-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:22.661-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23815 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:49.987-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:33.048-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-12.el6_4" test_ref="oval:org.mitre.oval:tst:111434"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-12.el6_4" test_ref="oval:org.mitre.oval:tst:111831"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-12.el6_4" test_ref="oval:org.mitre.oval:tst:110857"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23814" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0376: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference ref_id="ELSA-2012:0376-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0376.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0875" ref_url="http://linux.oracle.com/cve/CVE-2012-0875.html" source="CVE"/>
        <description>SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information from kernel memory or cause a denial of service (kernel panic and crash) via vectors related to crafted DWARF data, which triggers a read of an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:10.075-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:10.495-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:22.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23814 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:49.848-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:32.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="systemtap-runtime is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:110063"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109900"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109877"/>
            <criterion comment="systemtap is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109867"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109850"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:109794"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="systemtap-runtime is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109915"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:110108"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109921"/>
            <criterion comment="systemtap is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109781"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109976"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:110121"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:109818"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23813" version="189" class="patch">
      <metadata>
        <title>ELSA-2013:1507: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:1507-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1507.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3829" ref_url="http://linux.oracle.com/cve/CVE-2013-3829.html" source="CVE"/>
        <reference ref_id="CVE-2013-4041" ref_url="http://linux.oracle.com/cve/CVE-2013-4041.html" source="CVE"/>
        <reference ref_id="CVE-2013-5372" ref_url="http://linux.oracle.com/cve/CVE-2013-5372.html" source="CVE"/>
        <reference ref_id="CVE-2013-5375" ref_url="http://linux.oracle.com/cve/CVE-2013-5375.html" source="CVE"/>
        <reference ref_id="CVE-2013-5456" ref_url="http://linux.oracle.com/cve/CVE-2013-5456.html" source="CVE"/>
        <reference ref_id="CVE-2013-5457" ref_url="http://linux.oracle.com/cve/CVE-2013-5457.html" source="CVE"/>
        <reference ref_id="CVE-2013-5458" ref_url="http://linux.oracle.com/cve/CVE-2013-5458.html" source="CVE"/>
        <reference ref_id="CVE-2013-5772" ref_url="http://linux.oracle.com/cve/CVE-2013-5772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5776" ref_url="http://linux.oracle.com/cve/CVE-2013-5776.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5784" ref_url="http://linux.oracle.com/cve/CVE-2013-5784.html" source="CVE"/>
        <reference ref_id="CVE-2013-5787" ref_url="http://linux.oracle.com/cve/CVE-2013-5787.html" source="CVE"/>
        <reference ref_id="CVE-2013-5788" ref_url="http://linux.oracle.com/cve/CVE-2013-5788.html" source="CVE"/>
        <reference ref_id="CVE-2013-5789" ref_url="http://linux.oracle.com/cve/CVE-2013-5789.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5800" ref_url="http://linux.oracle.com/cve/CVE-2013-5800.html" source="CVE"/>
        <reference ref_id="CVE-2013-5801" ref_url="http://linux.oracle.com/cve/CVE-2013-5801.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5812" ref_url="http://linux.oracle.com/cve/CVE-2013-5812.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5818" ref_url="http://linux.oracle.com/cve/CVE-2013-5818.html" source="CVE"/>
        <reference ref_id="CVE-2013-5819" ref_url="http://linux.oracle.com/cve/CVE-2013-5819.html" source="CVE"/>
        <reference ref_id="CVE-2013-5820" ref_url="http://linux.oracle.com/cve/CVE-2013-5820.html" source="CVE"/>
        <reference ref_id="CVE-2013-5823" ref_url="http://linux.oracle.com/cve/CVE-2013-5823.html" source="CVE"/>
        <reference ref_id="CVE-2013-5824" ref_url="http://linux.oracle.com/cve/CVE-2013-5824.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5831" ref_url="http://linux.oracle.com/cve/CVE-2013-5831.html" source="CVE"/>
        <reference ref_id="CVE-2013-5832" ref_url="http://linux.oracle.com/cve/CVE-2013-5832.html" source="CVE"/>
        <reference ref_id="CVE-2013-5838" ref_url="http://linux.oracle.com/cve/CVE-2013-5838.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5843" ref_url="http://linux.oracle.com/cve/CVE-2013-5843.html" source="CVE"/>
        <reference ref_id="CVE-2013-5848" ref_url="http://linux.oracle.com/cve/CVE-2013-5848.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <reference ref_id="CVE-2013-5850" ref_url="http://linux.oracle.com/cve/CVE-2013-5850.html" source="CVE"/>
        <reference ref_id="CVE-2013-5851" ref_url="http://linux.oracle.com/cve/CVE-2013-5851.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:50:59.482-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:09.416-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:20.803-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23813 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:49.060-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:31.876-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112491"/>
          <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112271"/>
          <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112164"/>
          <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112520"/>
          <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112305"/>
          <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112329"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23812" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0376: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2014:0376-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0376.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0160" ref_url="http://linux.oracle.com/cve/CVE-2014-0160.html" source="CVE"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.
An information disclosure flaw was found in the way OpenSSL handled TLS and
DTLS Heartbeat Extension packets. A malicious TLS or DTLS client or server
could send a specially crafted TLS or DTLS Heartbeat packet to disclose a
limited portion of memory per request from a connected client or server.
Note that the disclosed portions of memory could potentially include
sensitive information such as private keys. (CVE-2014-0160)
Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges Neel Mehta of Google Security as the original
reporter.
All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T11:01:32.294-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:19.943-04:00">INTERIM</status_change>
            <modified comment="duplicate of oval:org.mitre.oval:def:24324" date="2014-06-27T10:22:47.225-04:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-06-27T10:22:47.225-04:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23812 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:114038"/>
          <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:114218"/>
          <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:113942"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:114187"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23811" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0169: vino security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference ref_id="ELSA-2013:0169-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0169.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0904" ref_url="http://linux.oracle.com/cve/CVE-2011-0904.html" source="CVE"/>
        <reference ref_id="CVE-2011-0905" ref_url="http://linux.oracle.com/cve/CVE-2011-0905.html" source="CVE"/>
        <reference ref_id="CVE-2011-1164" ref_url="http://linux.oracle.com/cve/CVE-2011-1164.html" source="CVE"/>
        <reference ref_id="CVE-2011-1165" ref_url="http://linux.oracle.com/cve/CVE-2011-1165.html" source="CVE"/>
        <reference ref_id="CVE-2012-4429" ref_url="http://linux.oracle.com/cve/CVE-2012-4429.html" source="CVE"/>
        <description>Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:32.663-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:09.261-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:20.561-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23811 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:56.135-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:31.670-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="vino is earlier than 0:2.28.1-8.el6_3" test_ref="oval:org.mitre.oval:tst:111196"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23809" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0058: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2012:0058-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0058.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-5029" ref_url="http://linux.oracle.com/cve/CVE-2009-5029.html" source="CVE"/>
        <reference ref_id="CVE-2011-4609" ref_url="http://linux.oracle.com/cve/CVE-2011-4609.html" source="CVE"/>
        <description>The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service (CPU consumption) via a large number of RPC connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:02.024-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:09.160-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:20.403-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23809 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:53.056-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:31.545-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="glibc-devel is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:109930"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:109875"/>
          <criterion comment="glibc is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:109701"/>
          <criterion comment="nscd is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:109910"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:109695"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:109135"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:108935"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23808" version="29" class="patch">
      <metadata>
        <title>ELSA-2012:0137: texlive security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>texlive</product>
        </affected>
        <reference ref_id="ELSA-2012:0137-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0137.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2642" ref_url="http://linux.oracle.com/cve/CVE-2010-2642.html" source="CVE"/>
        <reference ref_id="CVE-2011-0433" ref_url="http://linux.oracle.com/cve/CVE-2011-0433.html" source="CVE"/>
        <reference ref_id="CVE-2011-0764" ref_url="http://linux.oracle.com/cve/CVE-2011-0764.html" source="CVE"/>
        <reference ref_id="CVE-2011-1552" ref_url="http://linux.oracle.com/cve/CVE-2011-1552.html" source="CVE"/>
        <reference ref_id="CVE-2011-1553" ref_url="http://linux.oracle.com/cve/CVE-2011-1553.html" source="CVE"/>
        <reference ref_id="CVE-2011-1554" ref_url="http://linux.oracle.com/cve/CVE-2011-1554.html" source="CVE"/>
        <description>Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:03.713-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:08.902-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:20.092-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23808 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.649-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:31.335-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="texlive-dvips is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:109317"/>
          <criterion comment="texlive-latex is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:110084"/>
          <criterion comment="kpathsea is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:109874"/>
          <criterion comment="texlive-context is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:110062"/>
          <criterion comment="texlive-afm is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:109785"/>
          <criterion comment="mendexk is earlier than 0:2.6e-57.el6_2" test_ref="oval:org.mitre.oval:tst:109790"/>
          <criterion comment="texlive-dviutils is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:110055"/>
          <criterion comment="texlive-east-asian is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:109865"/>
          <criterion comment="texlive-utils is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:109960"/>
          <criterion comment="texlive-xetex is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:109947"/>
          <criterion comment="kpathsea-devel is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:109533"/>
          <criterion comment="texlive is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:109553"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23807" version="173" class="patch">
      <metadata>
        <title>ELSA-2013:0757: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2013:0757-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0757.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-0402" ref_url="http://linux.oracle.com/cve/CVE-2013-0402.html" source="CVE"/>
        <reference ref_id="CVE-2013-1488" ref_url="http://linux.oracle.com/cve/CVE-2013-1488.html" source="CVE"/>
        <reference ref_id="CVE-2013-1491" ref_url="http://linux.oracle.com/cve/CVE-2013-1491.html" source="CVE"/>
        <reference ref_id="CVE-2013-1518" ref_url="http://linux.oracle.com/cve/CVE-2013-1518.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1540" ref_url="http://linux.oracle.com/cve/CVE-2013-1540.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1558" ref_url="http://linux.oracle.com/cve/CVE-2013-1558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1561" ref_url="http://linux.oracle.com/cve/CVE-2013-1561.html" source="CVE"/>
        <reference ref_id="CVE-2013-1563" ref_url="http://linux.oracle.com/cve/CVE-2013-1563.html" source="CVE"/>
        <reference ref_id="CVE-2013-1564" ref_url="http://linux.oracle.com/cve/CVE-2013-1564.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2394" ref_url="http://linux.oracle.com/cve/CVE-2013-2394.html" source="CVE"/>
        <reference ref_id="CVE-2013-2414" ref_url="http://linux.oracle.com/cve/CVE-2013-2414.html" source="CVE"/>
        <reference ref_id="CVE-2013-2415" ref_url="http://linux.oracle.com/cve/CVE-2013-2415.html" source="CVE"/>
        <reference ref_id="CVE-2013-2416" ref_url="http://linux.oracle.com/cve/CVE-2013-2416.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2418" ref_url="http://linux.oracle.com/cve/CVE-2013-2418.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2421" ref_url="http://linux.oracle.com/cve/CVE-2013-2421.html" source="CVE"/>
        <reference ref_id="CVE-2013-2422" ref_url="http://linux.oracle.com/cve/CVE-2013-2422.html" source="CVE"/>
        <reference ref_id="CVE-2013-2423" ref_url="http://linux.oracle.com/cve/CVE-2013-2423.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2425" ref_url="http://linux.oracle.com/cve/CVE-2013-2425.html" source="CVE"/>
        <reference ref_id="CVE-2013-2426" ref_url="http://linux.oracle.com/cve/CVE-2013-2426.html" source="CVE"/>
        <reference ref_id="CVE-2013-2427" ref_url="http://linux.oracle.com/cve/CVE-2013-2427.html" source="CVE"/>
        <reference ref_id="CVE-2013-2428" ref_url="http://linux.oracle.com/cve/CVE-2013-2428.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2431" ref_url="http://linux.oracle.com/cve/CVE-2013-2431.html" source="CVE"/>
        <reference ref_id="CVE-2013-2432" ref_url="http://linux.oracle.com/cve/CVE-2013-2432.html" source="CVE"/>
        <reference ref_id="CVE-2013-2433" ref_url="http://linux.oracle.com/cve/CVE-2013-2433.html" source="CVE"/>
        <reference ref_id="CVE-2013-2434" ref_url="http://linux.oracle.com/cve/CVE-2013-2434.html" source="CVE"/>
        <reference ref_id="CVE-2013-2435" ref_url="http://linux.oracle.com/cve/CVE-2013-2435.html" source="CVE"/>
        <reference ref_id="CVE-2013-2436" ref_url="http://linux.oracle.com/cve/CVE-2013-2436.html" source="CVE"/>
        <reference ref_id="CVE-2013-2438" ref_url="http://linux.oracle.com/cve/CVE-2013-2438.html" source="CVE"/>
        <reference ref_id="CVE-2013-2439" ref_url="http://linux.oracle.com/cve/CVE-2013-2439.html" source="CVE"/>
        <reference ref_id="CVE-2013-2440" ref_url="http://linux.oracle.com/cve/CVE-2013-2440.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:49.610-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:07.802-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:18.406-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23807 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:52.359-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:30.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111592"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:112040"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111975"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111894"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111960"/>
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111790"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23806" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0149: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:0149-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0149.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0630" ref_url="http://linux.oracle.com/cve/CVE-2013-0630.html" source="CVE"/>
        <description>Buffer overflow in Adobe Flash Player before 10.3.183.50 and 11.x before 11.5.502.146 on Windows and Mac OS X, before 10.3.183.50 and 11.x before 11.2.202.261 on Linux, before 11.1.111.31 on Android 2.x and 3.x, and before 11.1.115.36 on Android 4.x; Adobe AIR before 3.5.0.1060; and Adobe AIR SDK before 3.5.0.1060 allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:19.868-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:07.722-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:18.311-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23806 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:55.204-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:30.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.261-1.el6" test_ref="oval:org.mitre.oval:tst:110747"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23805" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1221: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2012:1221-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1221.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0547" ref_url="http://linux.oracle.com/cve/CVE-2012-0547.html" source="CVE"/>
        <reference ref_id="CVE-2012-1682" ref_url="http://linux.oracle.com/cve/CVE-2012-1682.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136.	NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "XMLDecoder security issue via ClassFinder."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:52.131-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:07.477-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:18.235-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23805 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:53.941-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:30.159-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:110883"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:110926"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:110910"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:110643"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:110963"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23804" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0427: libtasn1 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtasn1</product>
        </affected>
        <reference ref_id="ELSA-2012:0427-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0427.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1569" ref_url="http://linux.oracle.com/cve/CVE-2012-1569.html" source="CVE"/>
        <description>The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:12.920-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:07.302-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:18.129-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23804 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:48.128-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:30.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libtasn1-tools is earlier than 0:2.3-3.el6_2.1" test_ref="oval:org.mitre.oval:tst:110054"/>
          <criterion comment="libtasn1 is earlier than 0:2.3-3.el6_2.1" test_ref="oval:org.mitre.oval:tst:109485"/>
          <criterion comment="libtasn1-devel is earlier than 0:2.3-3.el6_2.1" test_ref="oval:org.mitre.oval:tst:110002"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23802" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0568: dbus-glib security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dbus-glib</product>
        </affected>
        <reference ref_id="ELSA-2013:0568-03" ref_url="http://linux.oracle.com/errata/ELSA-2013-0568.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0292" ref_url="http://linux.oracle.com/cve/CVE-2013-0292.html" source="CVE"/>
        <description>The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:33.679-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:07.174-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:18.022-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23802 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.509-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:29.952-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:111559"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:111724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-glib is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:111522"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:111676"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23801" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1156: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2013:1156-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1156.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1896" ref_url="http://linux.oracle.com/cve/CVE-2013-1896.html" source="CVE"/>
        <description>mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:05.309-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:07.074-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:17.888-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23801 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.523-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:29.835-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="mod_ssl is earlier than 1:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:112368"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:111602"/>
            <criterion comment="httpd is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:112058"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:112390"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:112223"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="mod_ssl is earlier than 1:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:112020"/>
            <criterion comment="httpd is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:112217"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:112103"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:112346"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23800" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1091: nss, nspr, and nss-util security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference ref_id="ELSA-2012:1091-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1091.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0441" ref_url="http://linux.oracle.com/cve/CVE-2012-0441.html" source="CVE"/>
        <description>The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:45.370-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:06.973-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:17.761-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23800 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.819-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:29.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nss-util is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:110304"/>
          <criterion comment="nss-util-devel is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:110652"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:110454"/>
          <criterion comment="nss-tools is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:110181"/>
          <criterion comment="nss-sysinit is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:110708"/>
          <criterion comment="nss is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:110639"/>
          <criterion comment="nss-devel is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:110588"/>
          <criterion comment="nspr is earlier than 0:4.9.1-2.el6_3" test_ref="oval:org.mitre.oval:tst:110729"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.1-2.el6_3" test_ref="oval:org.mitre.oval:tst:110696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23799" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1206: python-paste-script security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python-paste-script</product>
        </affected>
        <reference ref_id="ELSA-2012:1206-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1206.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0878" ref_url="http://linux.oracle.com/cve/CVE-2012-0878.html" source="CVE"/>
        <description>Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:37.425-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:06.901-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:17.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23799 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:56.530-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:29.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="python-paste-script is earlier than 0:1.7.3-5.el6_3" test_ref="oval:org.mitre.oval:tst:110849"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23798" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0546: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0546-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0546.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1823" ref_url="http://linux.oracle.com/cve/CVE-2012-1823.html" source="CVE"/>
        <description>sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:20.231-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:06.739-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:17.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23798 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:47.372-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:29.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110119"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110178"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109644"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109653"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110090"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110145"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109700"/>
            <criterion comment="php is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109218"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109724"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109744"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109904"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110172"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109360"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110218"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109963"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109973"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:109843"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110078"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:110023"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110059"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110061"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109861"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109860"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110164"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109918"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110166"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109542"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110085"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109225"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109679"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109888"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109908"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109925"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109993"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110130"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110009"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109959"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109558"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109805"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109545"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109851"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:110105"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109740"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109760"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:109607"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23797" version="57" class="patch">
      <metadata>
        <title>ELSA-2012:1289: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2012:1289-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1289.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0547" ref_url="http://linux.oracle.com/cve/CVE-2012-0547.html" source="CVE"/>
        <reference ref_id="CVE-2012-0551" ref_url="http://linux.oracle.com/cve/CVE-2012-0551.html" source="CVE"/>
        <reference ref_id="CVE-2012-1682" ref_url="http://linux.oracle.com/cve/CVE-2012-1682.html" source="CVE"/>
        <reference ref_id="CVE-2012-1713" ref_url="http://linux.oracle.com/cve/CVE-2012-1713.html" source="CVE"/>
        <reference ref_id="CVE-2012-1716" ref_url="http://linux.oracle.com/cve/CVE-2012-1716.html" source="CVE"/>
        <reference ref_id="CVE-2012-1717" ref_url="http://linux.oracle.com/cve/CVE-2012-1717.html" source="CVE"/>
        <reference ref_id="CVE-2012-1719" ref_url="http://linux.oracle.com/cve/CVE-2012-1719.html" source="CVE"/>
        <reference ref_id="CVE-2012-1721" ref_url="http://linux.oracle.com/cve/CVE-2012-1721.html" source="CVE"/>
        <reference ref_id="CVE-2012-1722" ref_url="http://linux.oracle.com/cve/CVE-2012-1722.html" source="CVE"/>
        <reference ref_id="CVE-2012-1725" ref_url="http://linux.oracle.com/cve/CVE-2012-1725.html" source="CVE"/>
        <reference ref_id="CVE-2012-1726" ref_url="http://linux.oracle.com/cve/CVE-2012-1726.html" source="CVE"/>
        <reference ref_id="CVE-2012-3136" ref_url="http://linux.oracle.com/cve/CVE-2012-3136.html" source="CVE"/>
        <reference ref_id="CVE-2012-4681" ref_url="http://linux.oracle.com/cve/CVE-2012-4681.html" source="CVE"/>
        <description>Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:09.259-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:06.427-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:16.833-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23797 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:55.839-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:29.004-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111086"/>
          <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110830"/>
          <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111211"/>
          <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111140"/>
          <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111100"/>
          <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111002"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23796" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1141: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference ref_id="ELSA-2012:1141-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1141.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3571" ref_url="http://linux.oracle.com/cve/CVE-2012-3571.html" source="CVE"/>
        <reference ref_id="CVE-2012-3954" ref_url="http://linux.oracle.com/cve/CVE-2012-3954.html" source="CVE"/>
        <description>Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:49.959-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:06.311-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:16.699-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23796 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.927-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:28.894-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="dhclient is earlier than 12:4.1.1-31.P1.el6_3.1" test_ref="oval:org.mitre.oval:tst:110686"/>
          <criterion comment="dhcp-devel is earlier than 12:4.1.1-31.P1.el6_3.1" test_ref="oval:org.mitre.oval:tst:110925"/>
          <criterion comment="dhcp is earlier than 12:4.1.1-31.P1.el6_3.1" test_ref="oval:org.mitre.oval:tst:110586"/>
          <criterion comment="dhcp-common is earlier than 12:4.1.1-31.P1.el6_3.1" test_ref="oval:org.mitre.oval:tst:110602"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23795" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0052: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:0052-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0052.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0056" ref_url="http://linux.oracle.com/cve/CVE-2012-0056.html" source="CVE"/>
        <description>The mem_write function in Linux kernel 2.6.39 and other versions, when ASLR is disabled, does not properly check permissions when writing to /proc/&lt;pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:07.136-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:06.220-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:16.573-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23795 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.964-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:28.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109769"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109863"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109691"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109797"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109816"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109702"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109920"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109637"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109845"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109572"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109735"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:109651"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23794" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0126: openldap security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference ref_id="ELSA-2014:0126-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0126.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4449" ref_url="http://linux.oracle.com/cve/CVE-2013-4449.html" source="CVE"/>
        <description>The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:40.787-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:06.147-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:16.473-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23794 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:55.097-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:28.653-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openldap-servers is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:112792"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:112865"/>
          <criterion comment="openldap is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:112635"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:112837"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:112829"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23793" version="45" class="patch">
      <metadata>
        <title>ELSA-2012:0710: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0710-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0710.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3101" ref_url="http://linux.oracle.com/cve/CVE-2011-3101.html" source="CVE"/>
        <reference ref_id="CVE-2012-1937" ref_url="http://linux.oracle.com/cve/CVE-2012-1937.html" source="CVE"/>
        <reference ref_id="CVE-2012-1938" ref_url="http://linux.oracle.com/cve/CVE-2012-1938.html" source="CVE"/>
        <reference ref_id="CVE-2012-1939" ref_url="http://linux.oracle.com/cve/CVE-2012-1939.html" source="CVE"/>
        <reference ref_id="CVE-2012-1940" ref_url="http://linux.oracle.com/cve/CVE-2012-1940.html" source="CVE"/>
        <reference ref_id="CVE-2012-1941" ref_url="http://linux.oracle.com/cve/CVE-2012-1941.html" source="CVE"/>
        <reference ref_id="CVE-2012-1944" ref_url="http://linux.oracle.com/cve/CVE-2012-1944.html" source="CVE"/>
        <reference ref_id="CVE-2012-1945" ref_url="http://linux.oracle.com/cve/CVE-2012-1945.html" source="CVE"/>
        <reference ref_id="CVE-2012-1946" ref_url="http://linux.oracle.com/cve/CVE-2012-1946.html" source="CVE"/>
        <reference ref_id="CVE-2012-1947" ref_url="http://linux.oracle.com/cve/CVE-2012-1947.html" source="CVE"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:40.703-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:05.872-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:16.030-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23793 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.683-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:28.368-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:110020"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:110382"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:110254"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:109813"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:110485"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:110443"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23792" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:0080: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0080-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0080.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3659" ref_url="http://linux.oracle.com/cve/CVE-2011-3659.html" source="CVE"/>
        <reference ref_id="CVE-2011-3670" ref_url="http://linux.oracle.com/cve/CVE-2011-3670.html" source="CVE"/>
        <reference ref_id="CVE-2012-0442" ref_url="http://linux.oracle.com/cve/CVE-2012-0442.html" source="CVE"/>
        <reference ref_id="CVE-2012-0449" ref_url="http://linux.oracle.com/cve/CVE-2012-0449.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:09.614-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:05.726-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:15.832-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23792 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.387-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:28.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.18-1.el6_2" test_ref="oval:org.mitre.oval:tst:109556"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23791" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1441: icedtea-web security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference ref_id="ELSA-2011:1441-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1441.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3377" ref_url="http://linux.oracle.com/cve/CVE-2011-3377.html" source="CVE"/>
        <description>The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:56.062-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:05.627-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:15.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23791 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.416-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:28.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.0.6-1.el6_1" test_ref="oval:org.mitre.oval:tst:109409"/>
          <criterion comment="icedtea-web is earlier than 0:1.0.6-1.el6_1" test_ref="oval:org.mitre.oval:tst:109499"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23789" version="25" class="patch">
      <metadata>
        <title>ELSA-2012:1304: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1304-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1304.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2313" ref_url="http://linux.oracle.com/cve/CVE-2012-2313.html" source="CVE"/>
        <reference ref_id="CVE-2012-2384" ref_url="http://linux.oracle.com/cve/CVE-2012-2384.html" source="CVE"/>
        <reference ref_id="CVE-2012-2390" ref_url="http://linux.oracle.com/cve/CVE-2012-2390.html" source="CVE"/>
        <reference ref_id="CVE-2012-3430" ref_url="http://linux.oracle.com/cve/CVE-2012-3430.html" source="CVE"/>
        <reference ref_id="CVE-2012-3552" ref_url="http://linux.oracle.com/cve/CVE-2012-3552.html" source="CVE"/>
        <description>Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network traffic.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:11.176-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:05.378-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:15.414-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23789 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:53.305-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:27.952-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:110809"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:110650"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:110778"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:111185"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:110900"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:110949"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:111170"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:110247"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:111168"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:111032"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:111012"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:111036"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23786" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0143: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0143-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0143.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3026" ref_url="http://linux.oracle.com/cve/CVE-2011-3026.html" source="CVE"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:05.100-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:05.238-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:15.229-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23786 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.225-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:27.858-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:109339"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:109736"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:109919"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:110032"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23785" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0997: 389-ds-base security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference ref_id="ELSA-2012:0997-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0997.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2678" ref_url="http://linux.oracle.com/cve/CVE-2012-2678.html" source="CVE"/>
        <reference ref_id="CVE-2012-2746" ref_url="http://linux.oracle.com/cve/CVE-2012-2746.html" source="CVE"/>
        <description>389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:53.808-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:05.135-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:15.092-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23785 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:51.232-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:27.751-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="389-ds-base is earlier than 0:1.2.10.2-18.el6_3" test_ref="oval:org.mitre.oval:tst:110608"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.10.2-18.el6_3" test_ref="oval:org.mitre.oval:tst:110091"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.10.2-18.el6_3" test_ref="oval:org.mitre.oval:tst:110595"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23784" version="149" class="patch">
      <metadata>
        <title>ELSA-2013:0237: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2013:0237-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0237.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1541" ref_url="http://linux.oracle.com/cve/CVE-2012-1541.html" source="CVE"/>
        <reference ref_id="CVE-2012-3213" ref_url="http://linux.oracle.com/cve/CVE-2012-3213.html" source="CVE"/>
        <reference ref_id="CVE-2012-3342" ref_url="http://linux.oracle.com/cve/CVE-2012-3342.html" source="CVE"/>
        <reference ref_id="CVE-2013-0351" ref_url="http://linux.oracle.com/cve/CVE-2013-0351.html" source="CVE"/>
        <reference ref_id="CVE-2013-0409" ref_url="http://linux.oracle.com/cve/CVE-2013-0409.html" source="CVE"/>
        <reference ref_id="CVE-2013-0419" ref_url="http://linux.oracle.com/cve/CVE-2013-0419.html" source="CVE"/>
        <reference ref_id="CVE-2013-0423" ref_url="http://linux.oracle.com/cve/CVE-2013-0423.html" source="CVE"/>
        <reference ref_id="CVE-2013-0424" ref_url="http://linux.oracle.com/cve/CVE-2013-0424.html" source="CVE"/>
        <reference ref_id="CVE-2013-0425" ref_url="http://linux.oracle.com/cve/CVE-2013-0425.html" source="CVE"/>
        <reference ref_id="CVE-2013-0426" ref_url="http://linux.oracle.com/cve/CVE-2013-0426.html" source="CVE"/>
        <reference ref_id="CVE-2013-0427" ref_url="http://linux.oracle.com/cve/CVE-2013-0427.html" source="CVE"/>
        <reference ref_id="CVE-2013-0428" ref_url="http://linux.oracle.com/cve/CVE-2013-0428.html" source="CVE"/>
        <reference ref_id="CVE-2013-0429" ref_url="http://linux.oracle.com/cve/CVE-2013-0429.html" source="CVE"/>
        <reference ref_id="CVE-2013-0430" ref_url="http://linux.oracle.com/cve/CVE-2013-0430.html" source="CVE"/>
        <reference ref_id="CVE-2013-0431" ref_url="http://linux.oracle.com/cve/CVE-2013-0431.html" source="CVE"/>
        <reference ref_id="CVE-2013-0432" ref_url="http://linux.oracle.com/cve/CVE-2013-0432.html" source="CVE"/>
        <reference ref_id="CVE-2013-0433" ref_url="http://linux.oracle.com/cve/CVE-2013-0433.html" source="CVE"/>
        <reference ref_id="CVE-2013-0434" ref_url="http://linux.oracle.com/cve/CVE-2013-0434.html" source="CVE"/>
        <reference ref_id="CVE-2013-0435" ref_url="http://linux.oracle.com/cve/CVE-2013-0435.html" source="CVE"/>
        <reference ref_id="CVE-2013-0437" ref_url="http://linux.oracle.com/cve/CVE-2013-0437.html" source="CVE"/>
        <reference ref_id="CVE-2013-0438" ref_url="http://linux.oracle.com/cve/CVE-2013-0438.html" source="CVE"/>
        <reference ref_id="CVE-2013-0440" ref_url="http://linux.oracle.com/cve/CVE-2013-0440.html" source="CVE"/>
        <reference ref_id="CVE-2013-0441" ref_url="http://linux.oracle.com/cve/CVE-2013-0441.html" source="CVE"/>
        <reference ref_id="CVE-2013-0442" ref_url="http://linux.oracle.com/cve/CVE-2013-0442.html" source="CVE"/>
        <reference ref_id="CVE-2013-0443" ref_url="http://linux.oracle.com/cve/CVE-2013-0443.html" source="CVE"/>
        <reference ref_id="CVE-2013-0444" ref_url="http://linux.oracle.com/cve/CVE-2013-0444.html" source="CVE"/>
        <reference ref_id="CVE-2013-0445" ref_url="http://linux.oracle.com/cve/CVE-2013-0445.html" source="CVE"/>
        <reference ref_id="CVE-2013-0446" ref_url="http://linux.oracle.com/cve/CVE-2013-0446.html" source="CVE"/>
        <reference ref_id="CVE-2013-0448" ref_url="http://linux.oracle.com/cve/CVE-2013-0448.html" source="CVE"/>
        <reference ref_id="CVE-2013-0449" ref_url="http://linux.oracle.com/cve/CVE-2013-0449.html" source="CVE"/>
        <reference ref_id="CVE-2013-0450" ref_url="http://linux.oracle.com/cve/CVE-2013-0450.html" source="CVE"/>
        <reference ref_id="CVE-2013-1473" ref_url="http://linux.oracle.com/cve/CVE-2013-1473.html" source="CVE"/>
        <reference ref_id="CVE-2013-1475" ref_url="http://linux.oracle.com/cve/CVE-2013-1475.html" source="CVE"/>
        <reference ref_id="CVE-2013-1476" ref_url="http://linux.oracle.com/cve/CVE-2013-1476.html" source="CVE"/>
        <reference ref_id="CVE-2013-1478" ref_url="http://linux.oracle.com/cve/CVE-2013-1478.html" source="CVE"/>
        <reference ref_id="CVE-2013-1479" ref_url="http://linux.oracle.com/cve/CVE-2013-1479.html" source="CVE"/>
        <reference ref_id="CVE-2013-1480" ref_url="http://linux.oracle.com/cve/CVE-2013-1480.html" source="CVE"/>
        <reference ref_id="CVE-2013-1489" ref_url="http://linux.oracle.com/cve/CVE-2013-1489.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:22.492-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:04.273-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:13.734-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23784 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:53.783-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:26.953-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110736"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110683"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110954"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111164"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110999"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111336"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23783" version="53" class="patch">
      <metadata>
        <title>ELSA-2012:0515: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0515-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0515.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3062" ref_url="http://linux.oracle.com/cve/CVE-2011-3062.html" source="CVE"/>
        <reference ref_id="CVE-2012-0467" ref_url="http://linux.oracle.com/cve/CVE-2012-0467.html" source="CVE"/>
        <reference ref_id="CVE-2012-0468" ref_url="http://linux.oracle.com/cve/CVE-2012-0468.html" source="CVE"/>
        <reference ref_id="CVE-2012-0469" ref_url="http://linux.oracle.com/cve/CVE-2012-0469.html" source="CVE"/>
        <reference ref_id="CVE-2012-0470" ref_url="http://linux.oracle.com/cve/CVE-2012-0470.html" source="CVE"/>
        <reference ref_id="CVE-2012-0471" ref_url="http://linux.oracle.com/cve/CVE-2012-0471.html" source="CVE"/>
        <reference ref_id="CVE-2012-0472" ref_url="http://linux.oracle.com/cve/CVE-2012-0472.html" source="CVE"/>
        <reference ref_id="CVE-2012-0473" ref_url="http://linux.oracle.com/cve/CVE-2012-0473.html" source="CVE"/>
        <reference ref_id="CVE-2012-0474" ref_url="http://linux.oracle.com/cve/CVE-2012-0474.html" source="CVE"/>
        <reference ref_id="CVE-2012-0477" ref_url="http://linux.oracle.com/cve/CVE-2012-0477.html" source="CVE"/>
        <reference ref_id="CVE-2012-0478" ref_url="http://linux.oracle.com/cve/CVE-2012-0478.html" source="CVE"/>
        <reference ref_id="CVE-2012-0479" ref_url="http://linux.oracle.com/cve/CVE-2012-0479.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:18.680-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:03.965-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:13.265-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23783 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:56.652-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:26.612-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:109693"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:110186"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:110006"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:109623"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:110095"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:110183"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23782" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0742: 389-ds-base security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference ref_id="ELSA-2013:0742-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0742.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1897" ref_url="http://linux.oracle.com/cve/CVE-2013-1897.html" source="CVE"/>
        <description>The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:38.596-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:03.885-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:13.151-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23782 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:56.446-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:26.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-14.el6_4" test_ref="oval:org.mitre.oval:tst:111801"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-14.el6_4" test_ref="oval:org.mitre.oval:tst:111880"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-14.el6_4" test_ref="oval:org.mitre.oval:tst:111815"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23781" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0412: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2014:0412-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0412.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6629" ref_url="http://linux.oracle.com/cve/CVE-2013-6629.html" source="CVE"/>
        <reference ref_id="CVE-2013-6954" ref_url="http://linux.oracle.com/cve/CVE-2013-6954.html" source="CVE"/>
        <reference ref_id="CVE-2014-0429" ref_url="http://linux.oracle.com/cve/CVE-2014-0429.html" source="CVE"/>
        <reference ref_id="CVE-2014-0432" ref_url="http://linux.oracle.com/cve/CVE-2014-0432.html" source="CVE"/>
        <reference ref_id="CVE-2014-0446" ref_url="http://linux.oracle.com/cve/CVE-2014-0446.html" source="CVE"/>
        <reference ref_id="CVE-2014-0448" ref_url="http://linux.oracle.com/cve/CVE-2014-0448.html" source="CVE"/>
        <reference ref_id="CVE-2014-0449" ref_url="http://linux.oracle.com/cve/CVE-2014-0449.html" source="CVE"/>
        <reference ref_id="CVE-2014-0451" ref_url="http://linux.oracle.com/cve/CVE-2014-0451.html" source="CVE"/>
        <reference ref_id="CVE-2014-0452" ref_url="http://linux.oracle.com/cve/CVE-2014-0452.html" source="CVE"/>
        <reference ref_id="CVE-2014-0453" ref_url="http://linux.oracle.com/cve/CVE-2014-0453.html" source="CVE"/>
        <reference ref_id="CVE-2014-0454" ref_url="http://linux.oracle.com/cve/CVE-2014-0454.html" source="CVE"/>
        <reference ref_id="CVE-2014-0455" ref_url="http://linux.oracle.com/cve/CVE-2014-0455.html" source="CVE"/>
        <reference ref_id="CVE-2014-0456" ref_url="http://linux.oracle.com/cve/CVE-2014-0456.html" source="CVE"/>
        <reference ref_id="CVE-2014-0457" ref_url="http://linux.oracle.com/cve/CVE-2014-0457.html" source="CVE"/>
        <reference ref_id="CVE-2014-0458" ref_url="http://linux.oracle.com/cve/CVE-2014-0458.html" source="CVE"/>
        <reference ref_id="CVE-2014-0459" ref_url="http://linux.oracle.com/cve/CVE-2014-0459.html" source="CVE"/>
        <reference ref_id="CVE-2014-0460" ref_url="http://linux.oracle.com/cve/CVE-2014-0460.html" source="CVE"/>
        <reference ref_id="CVE-2014-0461" ref_url="http://linux.oracle.com/cve/CVE-2014-0461.html" source="CVE"/>
        <reference ref_id="CVE-2014-1876" ref_url="http://linux.oracle.com/cve/CVE-2014-1876.html" source="CVE"/>
        <reference ref_id="CVE-2014-2397" ref_url="http://linux.oracle.com/cve/CVE-2014-2397.html" source="CVE"/>
        <reference ref_id="CVE-2014-2398" ref_url="http://linux.oracle.com/cve/CVE-2014-2398.html" source="CVE"/>
        <reference ref_id="CVE-2014-2401" ref_url="http://linux.oracle.com/cve/CVE-2014-2401.html" source="CVE"/>
        <reference ref_id="CVE-2014-2402" ref_url="http://linux.oracle.com/cve/CVE-2014-2402.html" source="CVE"/>
        <reference ref_id="CVE-2014-2403" ref_url="http://linux.oracle.com/cve/CVE-2014-2403.html" source="CVE"/>
        <reference ref_id="CVE-2014-2409" ref_url="http://linux.oracle.com/cve/CVE-2014-2409.html" source="CVE"/>
        <reference ref_id="CVE-2014-2412" ref_url="http://linux.oracle.com/cve/CVE-2014-2412.html" source="CVE"/>
        <reference ref_id="CVE-2014-2413" ref_url="http://linux.oracle.com/cve/CVE-2014-2413.html" source="CVE"/>
        <reference ref_id="CVE-2014-2414" ref_url="http://linux.oracle.com/cve/CVE-2014-2414.html" source="CVE"/>
        <reference ref_id="CVE-2014-2420" ref_url="http://linux.oracle.com/cve/CVE-2014-2420.html" source="CVE"/>
        <reference ref_id="CVE-2014-2421" ref_url="http://linux.oracle.com/cve/CVE-2014-2421.html" source="CVE"/>
        <reference ref_id="CVE-2014-2422" ref_url="http://linux.oracle.com/cve/CVE-2014-2422.html" source="CVE"/>
        <reference ref_id="CVE-2014-2423" ref_url="http://linux.oracle.com/cve/CVE-2014-2423.html" source="CVE"/>
        <reference ref_id="CVE-2014-2427" ref_url="http://linux.oracle.com/cve/CVE-2014-2427.html" source="CVE"/>
        <reference ref_id="CVE-2014-2428" ref_url="http://linux.oracle.com/cve/CVE-2014-2428.html" source="CVE"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.
This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)
All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-15T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Ajin Cherian</contributor>
            </submitted>
            <status_change date="2014-05-22T10:59:37.600-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:17.393-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:54.489-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23781 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:32.031-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:56:00.595-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:56:00.595-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113278"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:114098"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113617"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113573"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113805"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113763"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114219"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114226"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113404"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114209"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113971"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23780" version="65" class="patch">
      <metadata>
        <title>ELSA-2012:1384: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2012:1384-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1384.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3216" ref_url="http://linux.oracle.com/cve/CVE-2012-3216.html" source="CVE"/>
        <reference ref_id="CVE-2012-4416" ref_url="http://linux.oracle.com/cve/CVE-2012-4416.html" source="CVE"/>
        <reference ref_id="CVE-2012-5068" ref_url="http://linux.oracle.com/cve/CVE-2012-5068.html" source="CVE"/>
        <reference ref_id="CVE-2012-5069" ref_url="http://linux.oracle.com/cve/CVE-2012-5069.html" source="CVE"/>
        <reference ref_id="CVE-2012-5071" ref_url="http://linux.oracle.com/cve/CVE-2012-5071.html" source="CVE"/>
        <reference ref_id="CVE-2012-5072" ref_url="http://linux.oracle.com/cve/CVE-2012-5072.html" source="CVE"/>
        <reference ref_id="CVE-2012-5073" ref_url="http://linux.oracle.com/cve/CVE-2012-5073.html" source="CVE"/>
        <reference ref_id="CVE-2012-5075" ref_url="http://linux.oracle.com/cve/CVE-2012-5075.html" source="CVE"/>
        <reference ref_id="CVE-2012-5077" ref_url="http://linux.oracle.com/cve/CVE-2012-5077.html" source="CVE"/>
        <reference ref_id="CVE-2012-5079" ref_url="http://linux.oracle.com/cve/CVE-2012-5079.html" source="CVE"/>
        <reference ref_id="CVE-2012-5081" ref_url="http://linux.oracle.com/cve/CVE-2012-5081.html" source="CVE"/>
        <reference ref_id="CVE-2012-5084" ref_url="http://linux.oracle.com/cve/CVE-2012-5084.html" source="CVE"/>
        <reference ref_id="CVE-2012-5085" ref_url="http://linux.oracle.com/cve/CVE-2012-5085.html" source="CVE"/>
        <reference ref_id="CVE-2012-5086" ref_url="http://linux.oracle.com/cve/CVE-2012-5086.html" source="CVE"/>
        <reference ref_id="CVE-2012-5089" ref_url="http://linux.oracle.com/cve/CVE-2012-5089.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:00.456-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:03.515-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:12.441-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23780 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.071-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:26.154-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:111203"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:110644"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:111035"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:111144"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:111031"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23779" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0987: sblim-cim-client2 security update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sblim-cim-client2</product>
        </affected>
        <reference ref_id="ELSA-2012:0987-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0987.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2328" ref_url="http://linux.oracle.com/cve/CVE-2012-2328.html" source="CVE"/>
        <description>internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:44.380-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:03.444-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:12.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23779 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:50.104-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:26.063-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="sblim-cim-client2-manual is earlier than 0:2.1.3-2.el6" test_ref="oval:org.mitre.oval:tst:110536"/>
          <criterion comment="sblim-cim-client2 is earlier than 0:2.1.3-2.el6" test_ref="oval:org.mitre.oval:tst:110493"/>
          <criterion comment="sblim-cim-client2-javadoc is earlier than 0:2.1.3-2.el6" test_ref="oval:org.mitre.oval:tst:110469"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23778" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1424: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference ref_id="ELSA-2011:1424-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1424.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2939" ref_url="http://linux.oracle.com/cve/CVE-2011-2939.html" source="CVE"/>
        <reference ref_id="CVE-2011-3597" ref_url="http://linux.oracle.com/cve/CVE-2011-3597.html" source="CVE"/>
        <description>Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:12.413-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:03.272-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:12.046-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23778 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:53.513-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:25.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="perl-libs is earlier than 4:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109282"/>
          <criterion comment="perl-suidperl is earlier than 4:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109340"/>
          <criterion comment="perl-core is earlier than 0:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109337"/>
          <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109345"/>
          <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109413"/>
          <criterion comment="perl-Package-Constants is earlier than 1:0.02-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109394"/>
          <criterion comment="perl-CGI is earlier than 0:3.51-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109543"/>
          <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109001"/>
          <criterion comment="perl-version is earlier than 3:0.77-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109395"/>
          <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109496"/>
          <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109441"/>
          <criterion comment="perl-Archive-Extract is earlier than 1:0.38-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:108868"/>
          <criterion comment="perl-Test-Simple is earlier than 0:0.92-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109474"/>
          <criterion comment="perl-Module-Loaded is earlier than 1:0.02-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:108562"/>
          <criterion comment="perl-Compress-Raw-Zlib is earlier than 0:2.023-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109498"/>
          <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109110"/>
          <criterion comment="perl-CPANPLUS is earlier than 0:0.88-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109072"/>
          <criterion comment="perl-parent is earlier than 1:0.221-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:108697"/>
          <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109401"/>
          <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109327"/>
          <criterion comment="perl-Test-Harness is earlier than 0:3.17-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109524"/>
          <criterion comment="perl-Module-Load is earlier than 1:0.16-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109300"/>
          <criterion comment="perl-Pod-Simple is earlier than 1:3.13-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109286"/>
          <criterion comment="perl-Params-Check is earlier than 1:0.26-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:108839"/>
          <criterion comment="perl-File-Fetch is earlier than 0:0.26-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109210"/>
          <criterion comment="perl-IO-Zlib is earlier than 1:1.09-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109078"/>
          <criterion comment="perl-Module-CoreList is earlier than 0:2.18-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109418"/>
          <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109526"/>
          <criterion comment="perl is earlier than 4:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109123"/>
          <criterion comment="perl-Time-Piece is earlier than 0:1.15-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109279"/>
          <criterion comment="perl-Digest-SHA is earlier than 1:5.47-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109099"/>
          <criterion comment="perl-Archive-Tar is earlier than 0:1.58-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109184"/>
          <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109370"/>
          <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109405"/>
          <criterion comment="perl-devel is earlier than 4:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109465"/>
          <criterion comment="perl-CPAN is earlier than 0:1.9402-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109371"/>
          <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109444"/>
          <criterion comment="perl-Object-Accessor is earlier than 1:0.34-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109475"/>
          <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109538"/>
          <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109264"/>
          <criterion comment="perl-Term-UI is earlier than 0:0.20-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109284"/>
          <criterion comment="perl-Module-Build is earlier than 1:0.3500-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109535"/>
          <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:108650"/>
          <criterion comment="perl-Log-Message is earlier than 1:0.02-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:109219"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23777" version="65" class="patch">
      <metadata>
        <title>ELSA-2013:0744: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0744-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0744.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6537" ref_url="http://linux.oracle.com/cve/CVE-2012-6537.html" source="CVE"/>
        <reference ref_id="CVE-2012-6538" ref_url="http://linux.oracle.com/cve/CVE-2012-6538.html" source="CVE"/>
        <reference ref_id="CVE-2012-6546" ref_url="http://linux.oracle.com/cve/CVE-2012-6546.html" source="CVE"/>
        <reference ref_id="CVE-2012-6547" ref_url="http://linux.oracle.com/cve/CVE-2012-6547.html" source="CVE"/>
        <reference ref_id="CVE-2013-0349" ref_url="http://linux.oracle.com/cve/CVE-2013-0349.html" source="CVE"/>
        <reference ref_id="CVE-2013-0913" ref_url="http://linux.oracle.com/cve/CVE-2013-0913.html" source="CVE"/>
        <reference ref_id="CVE-2013-1767" ref_url="http://linux.oracle.com/cve/CVE-2013-1767.html" source="CVE"/>
        <reference ref_id="CVE-2013-1773" ref_url="http://linux.oracle.com/cve/CVE-2013-1773.html" source="CVE"/>
        <reference ref_id="CVE-2013-1774" ref_url="http://linux.oracle.com/cve/CVE-2013-1774.html" source="CVE"/>
        <reference ref_id="CVE-2013-1792" ref_url="http://linux.oracle.com/cve/CVE-2013-1792.html" source="CVE"/>
        <reference ref_id="CVE-2013-1796" ref_url="http://linux.oracle.com/cve/CVE-2013-1796.html" source="CVE"/>
        <reference ref_id="CVE-2013-1797" ref_url="http://linux.oracle.com/cve/CVE-2013-1797.html" source="CVE"/>
        <reference ref_id="CVE-2013-1798" ref_url="http://linux.oracle.com/cve/CVE-2013-1798.html" source="CVE"/>
        <reference ref_id="CVE-2013-1826" ref_url="http://linux.oracle.com/cve/CVE-2013-1826.html" source="CVE"/>
        <reference ref_id="CVE-2013-1827" ref_url="http://linux.oracle.com/cve/CVE-2013-1827.html" source="CVE"/>
        <description>net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:47.218-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:02.873-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:11.304-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23777 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:55.490-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:25.455-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111618"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111916"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111716"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111788"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111927"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:112011"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111918"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111544"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111039"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111020"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111731"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:111968"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23773" version="29" class="patch">
      <metadata>
        <title>ELSA-2012:0062: t1lib security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>t1lib</product>
        </affected>
        <reference ref_id="ELSA-2012:0062-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0062.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2642" ref_url="http://linux.oracle.com/cve/CVE-2010-2642.html" source="CVE"/>
        <reference ref_id="CVE-2011-0433" ref_url="http://linux.oracle.com/cve/CVE-2011-0433.html" source="CVE"/>
        <reference ref_id="CVE-2011-0764" ref_url="http://linux.oracle.com/cve/CVE-2011-0764.html" source="CVE"/>
        <reference ref_id="CVE-2011-1552" ref_url="http://linux.oracle.com/cve/CVE-2011-1552.html" source="CVE"/>
        <reference ref_id="CVE-2011-1553" ref_url="http://linux.oracle.com/cve/CVE-2011-1553.html" source="CVE"/>
        <reference ref_id="CVE-2011-1554" ref_url="http://linux.oracle.com/cve/CVE-2011-1554.html" source="CVE"/>
        <description>Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:19.286-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:02.503-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:10.782-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23773 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:49.577-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:25.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="t1lib is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:109779"/>
          <criterion comment="t1lib-apps is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:109609"/>
          <criterion comment="t1lib-devel is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:109460"/>
          <criterion comment="t1lib-static is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:109664"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23772" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:1441: rubygems security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>rubygems</product>
        </affected>
        <reference ref_id="ELSA-2013:1441-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1441.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2005" ref_url="http://linux.oracle.com/cve/CVE-2012-2005.html" source="CVE"/>
        <reference ref_id="CVE-2012-2126" ref_url="http://linux.oracle.com/cve/CVE-2012-2126.html" source="CVE"/>
        <reference ref_id="CVE-2013-4287" ref_url="http://linux.oracle.com/cve/CVE-2013-4287.html" source="CVE"/>
        <description>Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:14.238-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:02.400-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:10.622-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23772 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:51.505-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:24.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="rubygems is earlier than 0:1.3.7-4.el6_4" test_ref="oval:org.mitre.oval:tst:112351"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23771" version="109" class="patch">
      <metadata>
        <title>ELSA-2013:0826: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2013:0826-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0826.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2549" ref_url="http://linux.oracle.com/cve/CVE-2013-2549.html" source="CVE"/>
        <reference ref_id="CVE-2013-2718" ref_url="http://linux.oracle.com/cve/CVE-2013-2718.html" source="CVE"/>
        <reference ref_id="CVE-2013-2719" ref_url="http://linux.oracle.com/cve/CVE-2013-2719.html" source="CVE"/>
        <reference ref_id="CVE-2013-2720" ref_url="http://linux.oracle.com/cve/CVE-2013-2720.html" source="CVE"/>
        <reference ref_id="CVE-2013-2721" ref_url="http://linux.oracle.com/cve/CVE-2013-2721.html" source="CVE"/>
        <reference ref_id="CVE-2013-2722" ref_url="http://linux.oracle.com/cve/CVE-2013-2722.html" source="CVE"/>
        <reference ref_id="CVE-2013-2723" ref_url="http://linux.oracle.com/cve/CVE-2013-2723.html" source="CVE"/>
        <reference ref_id="CVE-2013-2724" ref_url="http://linux.oracle.com/cve/CVE-2013-2724.html" source="CVE"/>
        <reference ref_id="CVE-2013-2725" ref_url="http://linux.oracle.com/cve/CVE-2013-2725.html" source="CVE"/>
        <reference ref_id="CVE-2013-2726" ref_url="http://linux.oracle.com/cve/CVE-2013-2726.html" source="CVE"/>
        <reference ref_id="CVE-2013-2727" ref_url="http://linux.oracle.com/cve/CVE-2013-2727.html" source="CVE"/>
        <reference ref_id="CVE-2013-2729" ref_url="http://linux.oracle.com/cve/CVE-2013-2729.html" source="CVE"/>
        <reference ref_id="CVE-2013-2730" ref_url="http://linux.oracle.com/cve/CVE-2013-2730.html" source="CVE"/>
        <reference ref_id="CVE-2013-2731" ref_url="http://linux.oracle.com/cve/CVE-2013-2731.html" source="CVE"/>
        <reference ref_id="CVE-2013-2732" ref_url="http://linux.oracle.com/cve/CVE-2013-2732.html" source="CVE"/>
        <reference ref_id="CVE-2013-2733" ref_url="http://linux.oracle.com/cve/CVE-2013-2733.html" source="CVE"/>
        <reference ref_id="CVE-2013-2734" ref_url="http://linux.oracle.com/cve/CVE-2013-2734.html" source="CVE"/>
        <reference ref_id="CVE-2013-2735" ref_url="http://linux.oracle.com/cve/CVE-2013-2735.html" source="CVE"/>
        <reference ref_id="CVE-2013-2736" ref_url="http://linux.oracle.com/cve/CVE-2013-2736.html" source="CVE"/>
        <reference ref_id="CVE-2013-2737" ref_url="http://linux.oracle.com/cve/CVE-2013-2737.html" source="CVE"/>
        <reference ref_id="CVE-2013-3337" ref_url="http://linux.oracle.com/cve/CVE-2013-3337.html" source="CVE"/>
        <reference ref_id="CVE-2013-3338" ref_url="http://linux.oracle.com/cve/CVE-2013-3338.html" source="CVE"/>
        <reference ref_id="CVE-2013-3339" ref_url="http://linux.oracle.com/cve/CVE-2013-3339.html" source="CVE"/>
        <reference ref_id="CVE-2013-3340" ref_url="http://linux.oracle.com/cve/CVE-2013-3340.html" source="CVE"/>
        <reference ref_id="CVE-2013-3341" ref_url="http://linux.oracle.com/cve/CVE-2013-3341.html" source="CVE"/>
        <reference ref_id="CVE-2013-3346" ref_url="http://linux.oracle.com/cve/CVE-2013-3346.html" source="CVE"/>
        <description>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:41.139-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:01.814-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:09.600-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23771 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:56.291-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:24.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="acroread-plugin is earlier than 0:9.5.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:111330"/>
          <criterion comment="acroread is earlier than 0:9.5.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:112016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23770" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:0678: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:0678-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0678.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0866" ref_url="http://linux.oracle.com/cve/CVE-2012-0866.html" source="CVE"/>
        <reference ref_id="CVE-2012-0867" ref_url="http://linux.oracle.com/cve/CVE-2012-0867.html" source="CVE"/>
        <reference ref_id="CVE-2012-0868" ref_url="http://linux.oracle.com/cve/CVE-2012-0868.html" source="CVE"/>
        <description>CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:33.822-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:01.634-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:09.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23770 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:49.328-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:24.170-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109738"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109949"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110133"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110096"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109667"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110229"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109290"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109270"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110333"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110177"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:110159"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:109342"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:109657"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110341"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110267"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110246"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110160"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110249"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:109942"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:109561"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110230"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:110281"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23768" version="61" class="patch">
      <metadata>
        <title>ELSA-2012:0467: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2012:0467-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0467.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1126" ref_url="http://linux.oracle.com/cve/CVE-2012-1126.html" source="CVE"/>
        <reference ref_id="CVE-2012-1127" ref_url="http://linux.oracle.com/cve/CVE-2012-1127.html" source="CVE"/>
        <reference ref_id="CVE-2012-1130" ref_url="http://linux.oracle.com/cve/CVE-2012-1130.html" source="CVE"/>
        <reference ref_id="CVE-2012-1131" ref_url="http://linux.oracle.com/cve/CVE-2012-1131.html" source="CVE"/>
        <reference ref_id="CVE-2012-1132" ref_url="http://linux.oracle.com/cve/CVE-2012-1132.html" source="CVE"/>
        <reference ref_id="CVE-2012-1134" ref_url="http://linux.oracle.com/cve/CVE-2012-1134.html" source="CVE"/>
        <reference ref_id="CVE-2012-1136" ref_url="http://linux.oracle.com/cve/CVE-2012-1136.html" source="CVE"/>
        <reference ref_id="CVE-2012-1137" ref_url="http://linux.oracle.com/cve/CVE-2012-1137.html" source="CVE"/>
        <reference ref_id="CVE-2012-1139" ref_url="http://linux.oracle.com/cve/CVE-2012-1139.html" source="CVE"/>
        <reference ref_id="CVE-2012-1140" ref_url="http://linux.oracle.com/cve/CVE-2012-1140.html" source="CVE"/>
        <reference ref_id="CVE-2012-1141" ref_url="http://linux.oracle.com/cve/CVE-2012-1141.html" source="CVE"/>
        <reference ref_id="CVE-2012-1142" ref_url="http://linux.oracle.com/cve/CVE-2012-1142.html" source="CVE"/>
        <reference ref_id="CVE-2012-1143" ref_url="http://linux.oracle.com/cve/CVE-2012-1143.html" source="CVE"/>
        <reference ref_id="CVE-2012-1144" ref_url="http://linux.oracle.com/cve/CVE-2012-1144.html" source="CVE"/>
        <description>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:07.365-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:01.226-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:08.756-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23768 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:55.997-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.820-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:109745"/>
            <criterion comment="freetype is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:110076"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:109509"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:110132"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:109997"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:109716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23767" version="37" class="patch">
      <metadata>
        <title>ELSA-2013:1269: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1269-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1269.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1718" ref_url="http://linux.oracle.com/cve/CVE-2013-1718.html" source="CVE"/>
        <reference ref_id="CVE-2013-1722" ref_url="http://linux.oracle.com/cve/CVE-2013-1722.html" source="CVE"/>
        <reference ref_id="CVE-2013-1725" ref_url="http://linux.oracle.com/cve/CVE-2013-1725.html" source="CVE"/>
        <reference ref_id="CVE-2013-1730" ref_url="http://linux.oracle.com/cve/CVE-2013-1730.html" source="CVE"/>
        <reference ref_id="CVE-2013-1732" ref_url="http://linux.oracle.com/cve/CVE-2013-1732.html" source="CVE"/>
        <reference ref_id="CVE-2013-1735" ref_url="http://linux.oracle.com/cve/CVE-2013-1735.html" source="CVE"/>
        <reference ref_id="CVE-2013-1736" ref_url="http://linux.oracle.com/cve/CVE-2013-1736.html" source="CVE"/>
        <reference ref_id="CVE-2013-1737" ref_url="http://linux.oracle.com/cve/CVE-2013-1737.html" source="CVE"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:01.815-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:01.021-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:08.396-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23767 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:47.694-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.559-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:112433"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:111848"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23766" version="29" class="patch">
      <metadata>
        <title>ELSA-2014:0132: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0132-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0132.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1477" ref_url="http://linux.oracle.com/cve/CVE-2014-1477.html" source="CVE"/>
        <reference ref_id="CVE-2014-1479" ref_url="http://linux.oracle.com/cve/CVE-2014-1479.html" source="CVE"/>
        <reference ref_id="CVE-2014-1481" ref_url="http://linux.oracle.com/cve/CVE-2014-1481.html" source="CVE"/>
        <reference ref_id="CVE-2014-1482" ref_url="http://linux.oracle.com/cve/CVE-2014-1482.html" source="CVE"/>
        <reference ref_id="CVE-2014-1486" ref_url="http://linux.oracle.com/cve/CVE-2014-1486.html" source="CVE"/>
        <reference ref_id="CVE-2014-1487" ref_url="http://linux.oracle.com/cve/CVE-2014-1487.html" source="CVE"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:38.893-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.821-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:08.119-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23766 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:52.657-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:111899"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:112883"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23765" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1328: qt security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference ref_id="ELSA-2011:1328-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1328.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3193" ref_url="http://linux.oracle.com/cve/CVE-2011-3193.html" source="CVE"/>
        <reference ref_id="CVE-2011-3194" ref_url="http://linux.oracle.com/cve/CVE-2011-3194.html" source="CVE"/>
        <description>Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the TIFFTAG_SAMPLESPERPIXEL tag in a greyscale TIFF image with multiple samples per pixel.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:58.441-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.671-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:07.946-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23765 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:54.207-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.235-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qt-odbc is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:109133"/>
          <criterion comment="qt-demos is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:109171"/>
          <criterion comment="qt-mysql is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:109399"/>
          <criterion comment="qt-x11 is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:108979"/>
          <criterion comment="qt-doc is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:109410"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:109274"/>
          <criterion comment="qt-postgresql is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:109391"/>
          <criterion comment="qt-sqlite is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:109247"/>
          <criterion comment="qt is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:109138"/>
          <criterion comment="qt-examples is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:109147"/>
          <criterion comment="qt-devel is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:108732"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23764" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0827: openswan security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2013:0827-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0827.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2053" ref_url="http://linux.oracle.com/cve/CVE-2013-2053.html" source="CVE"/>
        <description>Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records.	 NOTE: this might be the same vulnerability as CVE-2013-2052 and CVE-2013-2054.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:34.609-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.595-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:07.841-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23764 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:51.358-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:111989"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:111580"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:111657"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:111709"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23763" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1359: xorg-x11-server security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference ref_id="ELSA-2011:1359-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1359.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4818" ref_url="http://linux.oracle.com/cve/CVE-2010-4818.html" source="CVE"/>
        <reference ref_id="CVE-2010-4819" ref_url="http://linux.oracle.com/cve/CVE-2010-4819.html" source="CVE"/>
        <description>The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:03.828-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.484-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:07.665-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23763 - optimisation of Oracle Linux content" date="2014-05-05T17:26:00.915-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:27:52.859-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:23.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109266"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109352"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:108472"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109348"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109436"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109067"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109197"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:109190"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109134"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109433"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109458"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109414"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109025"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109406"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109269"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109208"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:109141"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23762" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0136: libvorbis security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 4</platform>
          <product>libvorbis</product>
        </affected>
        <reference ref_id="ELSA-2012:0136-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0136.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0444" ref_url="http://linux.oracle.com/cve/CVE-2012-0444.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:06.249-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.404-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:07.534-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23762 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:29.584-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:55:25.644-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:55:25.644-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libvorbis is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:109389"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:110000"/>
            <criterion comment="libvorbis-devel-docs is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:109624"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5_7.6" test_ref="oval:org.mitre.oval:tst:109622"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_7.6" test_ref="oval:org.mitre.oval:tst:109883"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23761" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1391: httpd security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2011:1391-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1391.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3348" ref_url="http://linux.oracle.com/cve/CVE-2011-3348.html" source="CVE"/>
        <reference ref_id="CVE-2011-3368" ref_url="http://linux.oracle.com/cve/CVE-2011-3368.html" source="CVE"/>
        <description>The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:53.537-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:00.310-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:07.376-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23761 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.612-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:22.891-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:109416"/>
          <criterion comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:109455"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:109331"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:109055"/>
          <criterion comment="httpd is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:109106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23758" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:0451: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>rpm</product>
        </affected>
        <reference ref_id="ELSA-2012:0451-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0451.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0060" ref_url="http://linux.oracle.com/cve/CVE-2012-0060.html" source="CVE"/>
        <reference ref_id="CVE-2012-0061" ref_url="http://linux.oracle.com/cve/CVE-2012-0061.html" source="CVE"/>
        <reference ref_id="CVE-2012-0815" ref_url="http://linux.oracle.com/cve/CVE-2012-0815.html" source="CVE"/>
        <description>The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:16.884-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:59.939-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:06.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23758 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.099-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:22.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109636"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109834"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:110162"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109442"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:110109"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109246"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:109789"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109954"/>
            <criterion comment="rpm is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109725"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109798"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:110060"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109497"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:110101"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:109579"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23757" version="61" class="patch">
      <metadata>
        <title>ELSA-2012:1089: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1089-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1089.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1948" ref_url="http://linux.oracle.com/cve/CVE-2012-1948.html" source="CVE"/>
        <reference ref_id="CVE-2012-1951" ref_url="http://linux.oracle.com/cve/CVE-2012-1951.html" source="CVE"/>
        <reference ref_id="CVE-2012-1952" ref_url="http://linux.oracle.com/cve/CVE-2012-1952.html" source="CVE"/>
        <reference ref_id="CVE-2012-1953" ref_url="http://linux.oracle.com/cve/CVE-2012-1953.html" source="CVE"/>
        <reference ref_id="CVE-2012-1954" ref_url="http://linux.oracle.com/cve/CVE-2012-1954.html" source="CVE"/>
        <reference ref_id="CVE-2012-1955" ref_url="http://linux.oracle.com/cve/CVE-2012-1955.html" source="CVE"/>
        <reference ref_id="CVE-2012-1957" ref_url="http://linux.oracle.com/cve/CVE-2012-1957.html" source="CVE"/>
        <reference ref_id="CVE-2012-1958" ref_url="http://linux.oracle.com/cve/CVE-2012-1958.html" source="CVE"/>
        <reference ref_id="CVE-2012-1959" ref_url="http://linux.oracle.com/cve/CVE-2012-1959.html" source="CVE"/>
        <reference ref_id="CVE-2012-1961" ref_url="http://linux.oracle.com/cve/CVE-2012-1961.html" source="CVE"/>
        <reference ref_id="CVE-2012-1962" ref_url="http://linux.oracle.com/cve/CVE-2012-1962.html" source="CVE"/>
        <reference ref_id="CVE-2012-1963" ref_url="http://linux.oracle.com/cve/CVE-2012-1963.html" source="CVE"/>
        <reference ref_id="CVE-2012-1964" ref_url="http://linux.oracle.com/cve/CVE-2012-1964.html" source="CVE"/>
        <reference ref_id="CVE-2012-1967" ref_url="http://linux.oracle.com/cve/CVE-2012-1967.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:51.106-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:59.558-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:06.325-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23757 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.142-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:22.358-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el5_8" test_ref="oval:org.mitre.oval:tst:110283"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:110589"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23756" version="157" class="patch">
      <metadata>
        <title>ELSA-2013:0963: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2013:0963-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0963.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2400" ref_url="http://linux.oracle.com/cve/CVE-2013-2400.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2437" ref_url="http://linux.oracle.com/cve/CVE-2013-2437.html" source="CVE"/>
        <reference ref_id="CVE-2013-2442" ref_url="http://linux.oracle.com/cve/CVE-2013-2442.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2449" ref_url="http://linux.oracle.com/cve/CVE-2013-2449.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2451" ref_url="http://linux.oracle.com/cve/CVE-2013-2451.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2458" ref_url="http://linux.oracle.com/cve/CVE-2013-2458.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2460" ref_url="http://linux.oracle.com/cve/CVE-2013-2460.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2462" ref_url="http://linux.oracle.com/cve/CVE-2013-2462.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2464" ref_url="http://linux.oracle.com/cve/CVE-2013-2464.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2466" ref_url="http://linux.oracle.com/cve/CVE-2013-2466.html" source="CVE"/>
        <reference ref_id="CVE-2013-2468" ref_url="http://linux.oracle.com/cve/CVE-2013-2468.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <reference ref_id="CVE-2013-3744" ref_url="http://linux.oracle.com/cve/CVE-2013-3744.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:08.323-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.646-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:04.739-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23756 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.364-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:21.380-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111754"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111999"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112202"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112111"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112129"/>
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111586"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23755" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0275: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0275-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0275.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <reference ref_id="CVE-2013-1484" ref_url="http://linux.oracle.com/cve/CVE-2013-1484.html" source="CVE"/>
        <reference ref_id="CVE-2013-1485" ref_url="http://linux.oracle.com/cve/CVE-2013-1485.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:27.016-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.501-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:04.488-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23755 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.011-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:21.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:111067"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:110817"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:111459"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:111122"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:111375"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111512"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111420"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111381"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111439"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:111358"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23754" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1282: nss and nspr security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
          <product>nspr</product>
        </affected>
        <reference ref_id="ELSA-2011:1282-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1282.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.
Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities.
It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update renders any HTTPS certificates signed by that CA
as untrusted. This covers all uses of the certificates, including SSL,
S/MIME, and code signing. (BZ#734316)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
These updated packages upgrade NSS to version 3.12.10 on Red Hat Enterprise
Linux 4 and 5. As well, they upgrade NSPR to version 4.8.8 on Red Hat
Enterprise Linux 4 and 5, as required by the NSS update. The packages for
Red Hat Enterprise Linux 6 include a backported patch.
All NSS and NSPR users should upgrade to these updated packages, which
correct this issue. After installing the update, applications using NSS and
NSPR must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:18.457-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.429-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:04.378-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23754 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.259-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:21.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nspr is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:109162"/>
            <criterion comment="nspr-devel is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:109355"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:109276"/>
            <criterion comment="nss-tools is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:109356"/>
            <criterion comment="nss is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:109368"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:109309"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:109205"/>
            <criterion comment="nss-tools is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:108706"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:109051"/>
            <criterion comment="nss is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:109179"/>
            <criterion comment="nss-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:108866"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23753" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:0744: python security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python</product>
        </affected>
        <reference ref_id="ELSA-2012:0744-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0744.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4940" ref_url="http://linux.oracle.com/cve/CVE-2011-4940.html" source="CVE"/>
        <reference ref_id="CVE-2011-4944" ref_url="http://linux.oracle.com/cve/CVE-2011-4944.html" source="CVE"/>
        <reference ref_id="CVE-2012-0845" ref_url="http://linux.oracle.com/cve/CVE-2012-0845.html" source="CVE"/>
        <reference ref_id="CVE-2012-1150" ref_url="http://linux.oracle.com/cve/CVE-2012-1150.html" source="CVE"/>
        <description>Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:37.109-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.294-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:04.139-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23753 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.068-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:20.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="python-devel is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:110529"/>
          <criterion comment="python-test is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:110170"/>
          <criterion comment="tkinter is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:110255"/>
          <criterion comment="python is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:110151"/>
          <criterion comment="python-tools is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:110435"/>
          <criterion comment="python-libs is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:110375"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23752" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1116: perl-DBD-Pg security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>perl-DBD-Pg</product>
        </affected>
        <reference ref_id="ELSA-2012:1116-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1116.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1151" ref_url="http://linux.oracle.com/cve/CVE-2012-1151.html" source="CVE"/>
        <description>Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:54.746-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.224-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:04.032-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23752 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.739-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:20.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="perl-DBD-Pg is earlier than 0:1.49-4.el5_8" test_ref="oval:org.mitre.oval:tst:110730"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="perl-DBD-Pg is earlier than 0:2.15.1-4.el6_3" test_ref="oval:org.mitre.oval:tst:110301"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23751" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0407: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference ref_id="ELSA-2012:0407-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0407.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3045" ref_url="http://linux.oracle.com/cve/CVE-2011-3045.html" source="CVE"/>
        <description>Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:04.095-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.147-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:03.920-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23751 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:58.823-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:20.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:110080"/>
            <criterion comment="libpng is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:110139"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-static is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:109628"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:109857"/>
            <criterion comment="libpng is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:109916"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23750" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1317: cyrus-imapd security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference ref_id="ELSA-2011:1317-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1317.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3208" ref_url="http://linux.oracle.com/cve/CVE-2011-3208.html" source="CVE"/>
        <description>Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:52.858-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:58.060-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:03.783-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23750 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.639-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:20.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:109024"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:109379"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:108988"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:109144"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109074"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109258"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109125"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23749" version="53" class="patch">
      <metadata>
        <title>ELSA-2012:0508: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2012:0508-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0508.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3389" ref_url="http://linux.oracle.com/cve/CVE-2011-3389.html" source="CVE"/>
        <reference ref_id="CVE-2011-3557" ref_url="http://linux.oracle.com/cve/CVE-2011-3557.html" source="CVE"/>
        <reference ref_id="CVE-2011-3560" ref_url="http://linux.oracle.com/cve/CVE-2011-3560.html" source="CVE"/>
        <reference ref_id="CVE-2011-3563" ref_url="http://linux.oracle.com/cve/CVE-2011-3563.html" source="CVE"/>
        <reference ref_id="CVE-2012-0498" ref_url="http://linux.oracle.com/cve/CVE-2012-0498.html" source="CVE"/>
        <reference ref_id="CVE-2012-0499" ref_url="http://linux.oracle.com/cve/CVE-2012-0499.html" source="CVE"/>
        <reference ref_id="CVE-2012-0501" ref_url="http://linux.oracle.com/cve/CVE-2012-0501.html" source="CVE"/>
        <reference ref_id="CVE-2012-0502" ref_url="http://linux.oracle.com/cve/CVE-2012-0502.html" source="CVE"/>
        <reference ref_id="CVE-2012-0503" ref_url="http://linux.oracle.com/cve/CVE-2012-0503.html" source="CVE"/>
        <reference ref_id="CVE-2012-0505" ref_url="http://linux.oracle.com/cve/CVE-2012-0505.html" source="CVE"/>
        <reference ref_id="CVE-2012-0506" ref_url="http://linux.oracle.com/cve/CVE-2012-0506.html" source="CVE"/>
        <reference ref_id="CVE-2012-0507" ref_url="http://linux.oracle.com/cve/CVE-2012-0507.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.	NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:31.254-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:57.730-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:03.367-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23749 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.404-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:20.384-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:110004"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:109977"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:109713"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:109940"/>
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:109743"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:109965"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:109776"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23748" version="89" class="patch">
      <metadata>
        <title>ELSA-2013:1509: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:1509-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1509.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5774" ref_url="http://linux.oracle.com/cve/CVE-2013-5774.html" source="CVE"/>
        <reference ref_id="CVE-2013-5778" ref_url="http://linux.oracle.com/cve/CVE-2013-5778.html" source="CVE"/>
        <reference ref_id="CVE-2013-5780" ref_url="http://linux.oracle.com/cve/CVE-2013-5780.html" source="CVE"/>
        <reference ref_id="CVE-2013-5782" ref_url="http://linux.oracle.com/cve/CVE-2013-5782.html" source="CVE"/>
        <reference ref_id="CVE-2013-5783" ref_url="http://linux.oracle.com/cve/CVE-2013-5783.html" source="CVE"/>
        <reference ref_id="CVE-2013-5790" ref_url="http://linux.oracle.com/cve/CVE-2013-5790.html" source="CVE"/>
        <reference ref_id="CVE-2013-5797" ref_url="http://linux.oracle.com/cve/CVE-2013-5797.html" source="CVE"/>
        <reference ref_id="CVE-2013-5801" ref_url="http://linux.oracle.com/cve/CVE-2013-5801.html" source="CVE"/>
        <reference ref_id="CVE-2013-5802" ref_url="http://linux.oracle.com/cve/CVE-2013-5802.html" source="CVE"/>
        <reference ref_id="CVE-2013-5803" ref_url="http://linux.oracle.com/cve/CVE-2013-5803.html" source="CVE"/>
        <reference ref_id="CVE-2013-5804" ref_url="http://linux.oracle.com/cve/CVE-2013-5804.html" source="CVE"/>
        <reference ref_id="CVE-2013-5809" ref_url="http://linux.oracle.com/cve/CVE-2013-5809.html" source="CVE"/>
        <reference ref_id="CVE-2013-5814" ref_url="http://linux.oracle.com/cve/CVE-2013-5814.html" source="CVE"/>
        <reference ref_id="CVE-2013-5817" ref_url="http://linux.oracle.com/cve/CVE-2013-5817.html" source="CVE"/>
        <reference ref_id="CVE-2013-5825" ref_url="http://linux.oracle.com/cve/CVE-2013-5825.html" source="CVE"/>
        <reference ref_id="CVE-2013-5829" ref_url="http://linux.oracle.com/cve/CVE-2013-5829.html" source="CVE"/>
        <reference ref_id="CVE-2013-5830" ref_url="http://linux.oracle.com/cve/CVE-2013-5830.html" source="CVE"/>
        <reference ref_id="CVE-2013-5840" ref_url="http://linux.oracle.com/cve/CVE-2013-5840.html" source="CVE"/>
        <reference ref_id="CVE-2013-5842" ref_url="http://linux.oracle.com/cve/CVE-2013-5842.html" source="CVE"/>
        <reference ref_id="CVE-2013-5843" ref_url="http://linux.oracle.com/cve/CVE-2013-5843.html" source="CVE"/>
        <reference ref_id="CVE-2013-5849" ref_url="http://linux.oracle.com/cve/CVE-2013-5849.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to AWT.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:11.942-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:57.214-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:02.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23748 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:57.540-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:19.873-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112326"/>
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112469"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112096"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112232"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112219"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112489"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112237"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23747" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1261: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference ref_id="ELSA-2012:1261-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1261.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3524" ref_url="http://linux.oracle.com/cve/CVE-2012-3524.html" source="CVE"/>
        <description>libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable.  NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:49.769-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:57.142-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:02.351-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23747 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.875-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:19.776-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="dbus-devel is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:110214"/>
          <criterion comment="dbus is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:110885"/>
          <criterion comment="dbus-x11 is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:111146"/>
          <criterion comment="dbus-libs is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:110590"/>
          <criterion comment="dbus-doc is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:111049"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23746" version="53" class="patch">
      <metadata>
        <title>ELSA-2011:1380: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2011:1380-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1380.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3389" ref_url="http://linux.oracle.com/cve/CVE-2011-3389.html" source="CVE"/>
        <reference ref_id="CVE-2011-3521" ref_url="http://linux.oracle.com/cve/CVE-2011-3521.html" source="CVE"/>
        <reference ref_id="CVE-2011-3544" ref_url="http://linux.oracle.com/cve/CVE-2011-3544.html" source="CVE"/>
        <reference ref_id="CVE-2011-3547" ref_url="http://linux.oracle.com/cve/CVE-2011-3547.html" source="CVE"/>
        <reference ref_id="CVE-2011-3548" ref_url="http://linux.oracle.com/cve/CVE-2011-3548.html" source="CVE"/>
        <reference ref_id="CVE-2011-3551" ref_url="http://linux.oracle.com/cve/CVE-2011-3551.html" source="CVE"/>
        <reference ref_id="CVE-2011-3552" ref_url="http://linux.oracle.com/cve/CVE-2011-3552.html" source="CVE"/>
        <reference ref_id="CVE-2011-3553" ref_url="http://linux.oracle.com/cve/CVE-2011-3553.html" source="CVE"/>
        <reference ref_id="CVE-2011-3554" ref_url="http://linux.oracle.com/cve/CVE-2011-3554.html" source="CVE"/>
        <reference ref_id="CVE-2011-3556" ref_url="http://linux.oracle.com/cve/CVE-2011-3556.html" source="CVE"/>
        <reference ref_id="CVE-2011-3557" ref_url="http://linux.oracle.com/cve/CVE-2011-3557.html" source="CVE"/>
        <reference ref_id="CVE-2011-3558" ref_url="http://linux.oracle.com/cve/CVE-2011-3558.html" source="CVE"/>
        <reference ref_id="CVE-2011-3560" ref_url="http://linux.oracle.com/cve/CVE-2011-3560.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity, related to JSSE.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:01.220-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:56.806-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:01.775-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23746 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:58.666-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:19.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109037"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109386"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109431"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109087"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:109303"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:108661"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:109461"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:108875"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:109159"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:109449"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23745" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0475: tomcat6 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference ref_id="ELSA-2012:0475-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0475.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4858" ref_url="http://linux.oracle.com/cve/CVE-2011-4858.html" source="CVE"/>
        <reference ref_id="CVE-2012-0022" ref_url="http://linux.oracle.com/cve/CVE-2012-0022.html" source="CVE"/>
        <description>Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:13.167-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:56.698-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:01.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23745 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.281-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:19.258-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:109663"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:109742"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:110138"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:109170"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:109839"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:110154"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:109922"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:110064"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:109827"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23743" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:1166: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1166-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1166.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0084" ref_url="http://linux.oracle.com/cve/CVE-2011-0084.html" source="CVE"/>
        <reference ref_id="CVE-2011-2378" ref_url="http://linux.oracle.com/cve/CVE-2011-2378.html" source="CVE"/>
        <reference ref_id="CVE-2011-2982" ref_url="http://linux.oracle.com/cve/CVE-2011-2982.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:24.493-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:56.597-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:01.427-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23743 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:01.894-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:19.076-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.12-1.el6_1" test_ref="oval:org.mitre.oval:tst:109251"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23742" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0506: samba4 security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference ref_id="ELSA-2013:0506-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0506.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1182" ref_url="http://linux.oracle.com/cve/CVE-2012-1182.html" source="CVE"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:18.933-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:56.504-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:01.282-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23742 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.830-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:18.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111003"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:110799"/>
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:110931"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111568"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111223"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111477"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111576"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111467"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111113"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111484"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111186"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111403"/>
          <criterion comment="samba4 is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111465"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:111262"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23741" version="49" class="patch">
      <metadata>
        <title>ELSA-2011:0886: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:0886-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0886.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0083" ref_url="http://linux.oracle.com/cve/CVE-2011-0083.html" source="CVE"/>
        <reference ref_id="CVE-2011-0085" ref_url="http://linux.oracle.com/cve/CVE-2011-0085.html" source="CVE"/>
        <reference ref_id="CVE-2011-2362" ref_url="http://linux.oracle.com/cve/CVE-2011-2362.html" source="CVE"/>
        <reference ref_id="CVE-2011-2363" ref_url="http://linux.oracle.com/cve/CVE-2011-2363.html" source="CVE"/>
        <reference ref_id="CVE-2011-2364" ref_url="http://linux.oracle.com/cve/CVE-2011-2364.html" source="CVE"/>
        <reference ref_id="CVE-2011-2365" ref_url="http://linux.oracle.com/cve/CVE-2011-2365.html" source="CVE"/>
        <reference ref_id="CVE-2011-2374" ref_url="http://linux.oracle.com/cve/CVE-2011-2374.html" source="CVE"/>
        <reference ref_id="CVE-2011-2375" ref_url="http://linux.oracle.com/cve/CVE-2011-2375.html" source="CVE"/>
        <reference ref_id="CVE-2011-2376" ref_url="http://linux.oracle.com/cve/CVE-2011-2376.html" source="CVE"/>
        <reference ref_id="CVE-2011-2377" ref_url="http://linux.oracle.com/cve/CVE-2011-2377.html" source="CVE"/>
        <reference ref_id="CVE-2011-2605" ref_url="http://linux.oracle.com/cve/CVE-2011-2605.html" source="CVE"/>
        <description>CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:17.397-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:56.229-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:06:00.775-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23741 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.538-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:18.675-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.11-2.el6_1" test_ref="oval:org.mitre.oval:tst:109082"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23740" version="113" class="patch">
      <metadata>
        <title>ELSA-2012:1391: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2012:1391-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1391.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1531" ref_url="http://linux.oracle.com/cve/CVE-2012-1531.html" source="CVE"/>
        <reference ref_id="CVE-2012-1532" ref_url="http://linux.oracle.com/cve/CVE-2012-1532.html" source="CVE"/>
        <reference ref_id="CVE-2012-1533" ref_url="http://linux.oracle.com/cve/CVE-2012-1533.html" source="CVE"/>
        <reference ref_id="CVE-2012-3143" ref_url="http://linux.oracle.com/cve/CVE-2012-3143.html" source="CVE"/>
        <reference ref_id="CVE-2012-3159" ref_url="http://linux.oracle.com/cve/CVE-2012-3159.html" source="CVE"/>
        <reference ref_id="CVE-2012-3216" ref_url="http://linux.oracle.com/cve/CVE-2012-3216.html" source="CVE"/>
        <reference ref_id="CVE-2012-4416" ref_url="http://linux.oracle.com/cve/CVE-2012-4416.html" source="CVE"/>
        <reference ref_id="CVE-2012-5067" ref_url="http://linux.oracle.com/cve/CVE-2012-5067.html" source="CVE"/>
        <reference ref_id="CVE-2012-5068" ref_url="http://linux.oracle.com/cve/CVE-2012-5068.html" source="CVE"/>
        <reference ref_id="CVE-2012-5069" ref_url="http://linux.oracle.com/cve/CVE-2012-5069.html" source="CVE"/>
        <reference ref_id="CVE-2012-5070" ref_url="http://linux.oracle.com/cve/CVE-2012-5070.html" source="CVE"/>
        <reference ref_id="CVE-2012-5071" ref_url="http://linux.oracle.com/cve/CVE-2012-5071.html" source="CVE"/>
        <reference ref_id="CVE-2012-5072" ref_url="http://linux.oracle.com/cve/CVE-2012-5072.html" source="CVE"/>
        <reference ref_id="CVE-2012-5073" ref_url="http://linux.oracle.com/cve/CVE-2012-5073.html" source="CVE"/>
        <reference ref_id="CVE-2012-5074" ref_url="http://linux.oracle.com/cve/CVE-2012-5074.html" source="CVE"/>
        <reference ref_id="CVE-2012-5075" ref_url="http://linux.oracle.com/cve/CVE-2012-5075.html" source="CVE"/>
        <reference ref_id="CVE-2012-5076" ref_url="http://linux.oracle.com/cve/CVE-2012-5076.html" source="CVE"/>
        <reference ref_id="CVE-2012-5077" ref_url="http://linux.oracle.com/cve/CVE-2012-5077.html" source="CVE"/>
        <reference ref_id="CVE-2012-5079" ref_url="http://linux.oracle.com/cve/CVE-2012-5079.html" source="CVE"/>
        <reference ref_id="CVE-2012-5081" ref_url="http://linux.oracle.com/cve/CVE-2012-5081.html" source="CVE"/>
        <reference ref_id="CVE-2012-5083" ref_url="http://linux.oracle.com/cve/CVE-2012-5083.html" source="CVE"/>
        <reference ref_id="CVE-2012-5084" ref_url="http://linux.oracle.com/cve/CVE-2012-5084.html" source="CVE"/>
        <reference ref_id="CVE-2012-5085" ref_url="http://linux.oracle.com/cve/CVE-2012-5085.html" source="CVE"/>
        <reference ref_id="CVE-2012-5086" ref_url="http://linux.oracle.com/cve/CVE-2012-5086.html" source="CVE"/>
        <reference ref_id="CVE-2012-5087" ref_url="http://linux.oracle.com/cve/CVE-2012-5087.html" source="CVE"/>
        <reference ref_id="CVE-2012-5088" ref_url="http://linux.oracle.com/cve/CVE-2012-5088.html" source="CVE"/>
        <reference ref_id="CVE-2012-5089" ref_url="http://linux.oracle.com/cve/CVE-2012-5089.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:06.030-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:55.625-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:59.719-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23740 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:59.421-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:18.100-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110526"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111078"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111061"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111016"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:111241"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:110886"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23739" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1815: icu security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>icu</product>
        </affected>
        <reference ref_id="ELSA-2011:1815-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1815.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4599" ref_url="http://linux.oracle.com/cve/CVE-2011-4599.html" source="CVE"/>
        <description>Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:16.771-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:55.543-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:59.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23739 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:59.834-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libicu-devel is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:109688"/>
            <criterion comment="libicu-doc is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:109227"/>
            <criterion comment="libicu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:109625"/>
            <criterion comment="icu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:109605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libicu-devel is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:109453"/>
            <criterion comment="libicu-doc is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:109692"/>
            <criterion comment="libicu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:109600"/>
            <criterion comment="icu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:108749"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23738" version="41" class="patch">
      <metadata>
        <title>ELSA-2013:0219: mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2013:0219-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0219.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0572" ref_url="http://linux.oracle.com/cve/CVE-2012-0572.html" source="CVE"/>
        <reference ref_id="CVE-2012-0574" ref_url="http://linux.oracle.com/cve/CVE-2012-0574.html" source="CVE"/>
        <reference ref_id="CVE-2012-1702" ref_url="http://linux.oracle.com/cve/CVE-2012-1702.html" source="CVE"/>
        <reference ref_id="CVE-2012-1705" ref_url="http://linux.oracle.com/cve/CVE-2012-1705.html" source="CVE"/>
        <reference ref_id="CVE-2013-0375" ref_url="http://linux.oracle.com/cve/CVE-2013-0375.html" source="CVE"/>
        <reference ref_id="CVE-2013-0383" ref_url="http://linux.oracle.com/cve/CVE-2013-0383.html" source="CVE"/>
        <reference ref_id="CVE-2013-0384" ref_url="http://linux.oracle.com/cve/CVE-2013-0384.html" source="CVE"/>
        <reference ref_id="CVE-2013-0385" ref_url="http://linux.oracle.com/cve/CVE-2013-0385.html" source="CVE"/>
        <reference ref_id="CVE-2013-0389" ref_url="http://linux.oracle.com/cve/CVE-2013-0389.html" source="CVE"/>
        <description>Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:32.264-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:55.309-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:59.158-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23738 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:01.559-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.763-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-server is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:110698"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:111149"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:110707"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:110994"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:111014"/>
          <criterion comment="mysql-test is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:111312"/>
          <criterion comment="mysql is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:111369"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:111081"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23737" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1359: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2012:1359-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1359.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4423" ref_url="http://linux.oracle.com/cve/CVE-2012-4423.html" source="CVE"/>
        <description>The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:07.856-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:55.232-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:59.040-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23737 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.696-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:110609"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:110985"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:111272"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:110986"/>
          <criterion comment="libvirt is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:110981"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23734" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:1379: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2011:1379-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1379.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1527" ref_url="http://linux.oracle.com/cve/CVE-2011-1527.html" source="CVE"/>
        <reference ref_id="CVE-2011-1528" ref_url="http://linux.oracle.com/cve/CVE-2011-1528.html" source="CVE"/>
        <reference ref_id="CVE-2011-1529" ref_url="http://linux.oracle.com/cve/CVE-2011-1529.html" source="CVE"/>
        <description>The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the db2 (aka Berkeley DB) or LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger certain process_as_req errors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:10.679-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:55.027-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:58.748-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23734 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:01.447-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.528-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-devel is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:108702"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:108626"/>
          <criterion comment="krb5-workstation is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109032"/>
          <criterion comment="krb5-libs is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109065"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109239"/>
          <criterion comment="krb5-server is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:108795"/>
          <criterion comment="krb5 is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109202"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23733" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0324: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:0324-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0324.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0841" ref_url="http://linux.oracle.com/cve/CVE-2012-0841.html" source="CVE"/>
        <description>libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:06.660-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.934-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:58.622-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23733 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.858-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.421-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:109811"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:109842"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:109157"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:109220"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:109422"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:109737"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:109945"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23731" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0869: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:0869-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0869.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2110" ref_url="http://linux.oracle.com/cve/CVE-2011-2110.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:16.846-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.776-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:58.428-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23731 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.782-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.331-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.26-1.el5" test_ref="oval:org.mitre.oval:tst:108641"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.26-1.el6" test_ref="oval:org.mitre.oval:tst:108967"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23730" version="61" class="patch">
      <metadata>
        <title>ELSA-2011:1144: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1144-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1144.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2130" ref_url="http://linux.oracle.com/cve/CVE-2011-2130.html" source="CVE"/>
        <reference ref_id="CVE-2011-2134" ref_url="http://linux.oracle.com/cve/CVE-2011-2134.html" source="CVE"/>
        <reference ref_id="CVE-2011-2135" ref_url="http://linux.oracle.com/cve/CVE-2011-2135.html" source="CVE"/>
        <reference ref_id="CVE-2011-2136" ref_url="http://linux.oracle.com/cve/CVE-2011-2136.html" source="CVE"/>
        <reference ref_id="CVE-2011-2137" ref_url="http://linux.oracle.com/cve/CVE-2011-2137.html" source="CVE"/>
        <reference ref_id="CVE-2011-2138" ref_url="http://linux.oracle.com/cve/CVE-2011-2138.html" source="CVE"/>
        <reference ref_id="CVE-2011-2139" ref_url="http://linux.oracle.com/cve/CVE-2011-2139.html" source="CVE"/>
        <reference ref_id="CVE-2011-2140" ref_url="http://linux.oracle.com/cve/CVE-2011-2140.html" source="CVE"/>
        <reference ref_id="CVE-2011-2414" ref_url="http://linux.oracle.com/cve/CVE-2011-2414.html" source="CVE"/>
        <reference ref_id="CVE-2011-2415" ref_url="http://linux.oracle.com/cve/CVE-2011-2415.html" source="CVE"/>
        <reference ref_id="CVE-2011-2416" ref_url="http://linux.oracle.com/cve/CVE-2011-2416.html" source="CVE"/>
        <reference ref_id="CVE-2011-2417" ref_url="http://linux.oracle.com/cve/CVE-2011-2417.html" source="CVE"/>
        <reference ref_id="CVE-2011-2424" ref_url="http://linux.oracle.com/cve/CVE-2011-2424.html" source="CVE"/>
        <reference ref_id="CVE-2011-2425" ref_url="http://linux.oracle.com/cve/CVE-2011-2425.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2135, CVE-2011-2140, and CVE-2011-2417.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:09.959-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.667-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:57.836-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23730 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:58.163-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.228-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el5" test_ref="oval:org.mitre.oval:tst:109242"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el6" test_ref="oval:org.mitre.oval:tst:109186"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23729" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0426: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2012:0426-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0426.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0884" ref_url="http://linux.oracle.com/cve/CVE-2012-0884.html" source="CVE"/>
        <reference ref_id="CVE-2012-1165" ref_url="http://linux.oracle.com/cve/CVE-2012-1165.html" source="CVE"/>
        <description>The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:07.988-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.516-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:57.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23729 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:57.058-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:109748"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:109588"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:109759"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:109723"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:109838"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:110081"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:109985"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23728" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0468: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2012:0468-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0468.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1173" ref_url="http://linux.oracle.com/cve/CVE-2012-1173.html" source="CVE"/>
        <description>Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:16.465-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.436-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:57.554-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23728 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.725-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:17.025-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:110149"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:109975"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libtiff is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:109878"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:110035"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:110123"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23727" version="17" class="patch">
      <metadata>
        <title>ELSA-2013:1035: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:1035-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1035.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-3344" ref_url="http://linux.oracle.com/cve/CVE-2013-3344.html" source="CVE"/>
        <reference ref_id="CVE-2013-3345" ref_url="http://linux.oracle.com/cve/CVE-2013-3345.html" source="CVE"/>
        <reference ref_id="CVE-2013-3347" ref_url="http://linux.oracle.com/cve/CVE-2013-3347.html" source="CVE"/>
        <description>Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:59.676-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.298-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:57.393-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23727 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.437-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:16.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.297-1.el6" test_ref="oval:org.mitre.oval:tst:112077"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23725" version="33" class="patch">
      <metadata>
        <title>ELSA-2011:1087: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:1087-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1087.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0802" ref_url="http://linux.oracle.com/cve/CVE-2011-0802.html" source="CVE"/>
        <reference ref_id="CVE-2011-0814" ref_url="http://linux.oracle.com/cve/CVE-2011-0814.html" source="CVE"/>
        <reference ref_id="CVE-2011-0862" ref_url="http://linux.oracle.com/cve/CVE-2011-0862.html" source="CVE"/>
        <reference ref_id="CVE-2011-0865" ref_url="http://linux.oracle.com/cve/CVE-2011-0865.html" source="CVE"/>
        <reference ref_id="CVE-2011-0867" ref_url="http://linux.oracle.com/cve/CVE-2011-0867.html" source="CVE"/>
        <reference ref_id="CVE-2011-0871" ref_url="http://linux.oracle.com/cve/CVE-2011-0871.html" source="CVE"/>
        <reference ref_id="CVE-2011-0873" ref_url="http://linux.oracle.com/cve/CVE-2011-0873.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:09.511-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:54.036-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:57.010-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23725 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.932-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:16.567-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109155"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108880"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109149"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108666"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108566"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109041"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108902"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108826"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108993"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109112"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109152"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109010"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108639"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108227"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108695"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23722" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1132: icedtea-web security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference ref_id="ELSA-2012:1132-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1132.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3422" ref_url="http://linux.oracle.com/cve/CVE-2012-3422.html" source="CVE"/>
        <reference ref_id="CVE-2012-3423" ref_url="http://linux.oracle.com/cve/CVE-2012-3423.html" source="CVE"/>
        <description>The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:43.172-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:53.945-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:56.864-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23722 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.733-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:16.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.2.1-1.el6_3" test_ref="oval:org.mitre.oval:tst:110785"/>
          <criterion comment="icedtea-web is earlier than 0:1.2.1-1.el6_3" test_ref="oval:org.mitre.oval:tst:110861"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23721" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0983: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2013:0983-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0983.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2174" ref_url="http://linux.oracle.com/cve/CVE-2013-2174.html" source="CVE"/>
        <description>Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:48:57.619-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:53.858-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:56.751-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23721 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:01.792-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:16.286-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:111925"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:111504"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:112249"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:112229"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:111617"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23720" version="45" class="patch">
      <metadata>
        <title>ELSA-2012:0135: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2012:0135-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0135.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3563" ref_url="http://linux.oracle.com/cve/CVE-2011-3563.html" source="CVE"/>
        <reference ref_id="CVE-2011-3571" ref_url="http://linux.oracle.com/cve/CVE-2011-3571.html" source="CVE"/>
        <reference ref_id="CVE-2011-5035" ref_url="http://linux.oracle.com/cve/CVE-2011-5035.html" source="CVE"/>
        <reference ref_id="CVE-2012-0497" ref_url="http://linux.oracle.com/cve/CVE-2012-0497.html" source="CVE"/>
        <reference ref_id="CVE-2012-0501" ref_url="http://linux.oracle.com/cve/CVE-2012-0501.html" source="CVE"/>
        <reference ref_id="CVE-2012-0502" ref_url="http://linux.oracle.com/cve/CVE-2012-0502.html" source="CVE"/>
        <reference ref_id="CVE-2012-0503" ref_url="http://linux.oracle.com/cve/CVE-2012-0503.html" source="CVE"/>
        <reference ref_id="CVE-2012-0505" ref_url="http://linux.oracle.com/cve/CVE-2012-0505.html" source="CVE"/>
        <reference ref_id="CVE-2012-0506" ref_url="http://linux.oracle.com/cve/CVE-2012-0506.html" source="CVE"/>
        <reference ref_id="CVE-2012-0507" ref_url="http://linux.oracle.com/cve/CVE-2012-0507.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.	NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:02.918-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:53.596-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:56.294-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23720 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:58.361-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:16.030-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:109929"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:110025"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:109415"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:109836"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:109649"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23719" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0215: abrt and libreport security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>abrt</product>
          <product>libreport</product>
        </affected>
        <reference ref_id="ELSA-2013:0215-03" ref_url="http://linux.oracle.com/errata/ELSA-2013-0215.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5659" ref_url="http://linux.oracle.com/cve/CVE-2012-5659.html" source="CVE"/>
        <reference ref_id="CVE-2012-5660" ref_url="http://linux.oracle.com/cve/CVE-2012-5660.html" source="CVE"/>
        <description>abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:28.998-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:53.469-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:56.099-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23719 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:59.658-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:15.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libreport-plugin-rhtsupport is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111254"/>
          <criterion comment="libreport-plugin-mailx is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111413"/>
          <criterion comment="libreport-gtk-devel is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111416"/>
          <criterion comment="libreport-python is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111382"/>
          <criterion comment="libreport-cli is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:110978"/>
          <criterion comment="libreport is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111013"/>
          <criterion comment="libreport-newt is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111290"/>
          <criterion comment="libreport-plugin-reportuploader is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111392"/>
          <criterion comment="libreport-gtk is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111329"/>
          <criterion comment="libreport-plugin-kerneloops is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111314"/>
          <criterion comment="libreport-devel is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111118"/>
          <criterion comment="libreport-plugin-logger is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111404"/>
          <criterion comment="libreport-plugin-bugzilla is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:111313"/>
          <criterion comment="abrt-desktop is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:110975"/>
          <criterion comment="abrt-gui is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:110453"/>
          <criterion comment="abrt is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:110996"/>
          <criterion comment="abrt-devel is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:111142"/>
          <criterion comment="abrt-addon-kerneloops is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:111148"/>
          <criterion comment="abrt-addon-vmcore is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:111383"/>
          <criterion comment="abrt-tui is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:110860"/>
          <criterion comment="abrt-addon-python is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:110672"/>
          <criterion comment="abrt-addon-ccpp is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:111357"/>
          <criterion comment="abrt-libs is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:111391"/>
          <criterion comment="abrt-cli is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:111320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23717" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:1437: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:1437-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1437.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3647" ref_url="http://linux.oracle.com/cve/CVE-2011-3647.html" source="CVE"/>
        <reference ref_id="CVE-2011-3648" ref_url="http://linux.oracle.com/cve/CVE-2011-3648.html" source="CVE"/>
        <reference ref_id="CVE-2011-3650" ref_url="http://linux.oracle.com/cve/CVE-2011-3650.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:59.097-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:53.348-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:55.883-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23717 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.529-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:15.645-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el5_7" test_ref="oval:org.mitre.oval:tst:109551"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.24-2.el5_7" test_ref="oval:org.mitre.oval:tst:109435"/>
            <criterion comment="firefox is earlier than 0:3.6.24-3.el5_7" test_ref="oval:org.mitre.oval:tst:109277"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109400"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.24-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109268"/>
            <criterion comment="firefox is earlier than 0:3.6.24-3.el6_1" test_ref="oval:org.mitre.oval:tst:109534"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23715" version="29" class="patch">
      <metadata>
        <title>ELSA-2012:0544: ImageMagick security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ImageMagick</product>
        </affected>
        <reference ref_id="ELSA-2012:0544-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0544.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4167" ref_url="http://linux.oracle.com/cve/CVE-2010-4167.html" source="CVE"/>
        <reference ref_id="CVE-2012-0247" ref_url="http://linux.oracle.com/cve/CVE-2012-0247.html" source="CVE"/>
        <reference ref_id="CVE-2012-0248" ref_url="http://linux.oracle.com/cve/CVE-2012-0248.html" source="CVE"/>
        <reference ref_id="CVE-2012-0259" ref_url="http://linux.oracle.com/cve/CVE-2012-0259.html" source="CVE"/>
        <reference ref_id="CVE-2012-0260" ref_url="http://linux.oracle.com/cve/CVE-2012-0260.html" source="CVE"/>
        <reference ref_id="CVE-2012-1798" ref_url="http://linux.oracle.com/cve/CVE-2012-1798.html" source="CVE"/>
        <description>The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:38.373-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:53.183-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:55.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23715 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:29:57.801-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:15.335-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ImageMagick-doc is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:109392"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:109683"/>
          <criterion comment="ImageMagick-devel is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:109478"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:110197"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:109931"/>
          <criterion comment="ImageMagick is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:109923"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23714" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1208: glibc security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2012:1208-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1208.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3480" ref_url="http://linux.oracle.com/cve/CVE-2012-3480.html" source="CVE"/>
        <description>Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:44.459-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:53.103-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:55.434-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23714 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.208-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:15.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="glibc-devel is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:110215"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:110587"/>
          <criterion comment="glibc is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:110834"/>
          <criterion comment="nscd is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:110556"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:110018"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:110764"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:110877"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23713" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1135: libreoffice security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libreoffice</product>
        </affected>
        <reference ref_id="ELSA-2012:1135-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1135.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2665" ref_url="http://linux.oracle.com/cve/CVE-2012-2665.html" source="CVE"/>
        <description>Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:36.469-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:52.767-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:55.031-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23713 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:01.152-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:14.731-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libreoffice-langpack-de is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110907"/>
          <criterion comment="libreoffice-langpack-sk is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110935"/>
          <criterion comment="libreoffice-langpack-hr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110741"/>
          <criterion comment="libreoffice-langpack-ro is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110351"/>
          <criterion comment="libreoffice-pyuno is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110815"/>
          <criterion comment="autocorr-af is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110614"/>
          <criterion comment="libreoffice-report-builder is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110801"/>
          <criterion comment="libreoffice-calc is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110783"/>
          <criterion comment="autocorr-vi is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110679"/>
          <criterion comment="libreoffice-langpack-ta is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110899"/>
          <criterion comment="libreoffice-math is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110748"/>
          <criterion comment="autocorr-ja is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110760"/>
          <criterion comment="autocorr-sr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110929"/>
          <criterion comment="libreoffice-langpack-bg is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:109950"/>
          <criterion comment="autocorr-eu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110660"/>
          <criterion comment="libreoffice-langpack-eu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110913"/>
          <criterion comment="libreoffice-langpack-ja is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110072"/>
          <criterion comment="libreoffice-langpack-or is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110823"/>
          <criterion comment="libreoffice-langpack-hi is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110555"/>
          <criterion comment="autocorr-sl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110786"/>
          <criterion comment="libreoffice-langpack-zu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:109946"/>
          <criterion comment="libreoffice-langpack-el is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110532"/>
          <criterion comment="autocorr-ga is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110794"/>
          <criterion comment="autocorr-mn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110434"/>
          <criterion comment="libreoffice-langpack-cy is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110723"/>
          <criterion comment="libreoffice is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110743"/>
          <criterion comment="libreoffice-langpack-ga is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110689"/>
          <criterion comment="autocorr-pl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110853"/>
          <criterion comment="libreoffice-bsh is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110942"/>
          <criterion comment="libreoffice-langpack-cs is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110465"/>
          <criterion comment="libreoffice-langpack-tn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110803"/>
          <criterion comment="libreoffice-base is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110720"/>
          <criterion comment="libreoffice-langpack-sr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110405"/>
          <criterion comment="autocorr-da is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110921"/>
          <criterion comment="libreoffice-pdfimport is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110852"/>
          <criterion comment="libreoffice-presenter-screen is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110379"/>
          <criterion comment="libreoffice-langpack-xh is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110745"/>
          <criterion comment="libreoffice-langpack-zh-Hans is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110870"/>
          <criterion comment="libreoffice-langpack-bn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110717"/>
          <criterion comment="libreoffice-graphicfilter is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110889"/>
          <criterion comment="libreoffice-langpack-sl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110500"/>
          <criterion comment="libreoffice-langpack-ar is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110705"/>
          <criterion comment="libreoffice-langpack-th is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110751"/>
          <criterion comment="autocorr-sv is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110905"/>
          <criterion comment="autocorr-tr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110631"/>
          <criterion comment="libreoffice-xsltfilter is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110894"/>
          <criterion comment="libreoffice-langpack-te is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110685"/>
          <criterion comment="autocorr-fr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110909"/>
          <criterion comment="autocorr-es is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110697"/>
          <criterion comment="libreoffice-langpack-uk is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110565"/>
          <criterion comment="libreoffice-langpack-fr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110193"/>
          <criterion comment="libreoffice-langpack-ca is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:109903"/>
          <criterion comment="libreoffice-javafilter is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110622"/>
          <criterion comment="libreoffice-langpack-af is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110825"/>
          <criterion comment="libreoffice-langpack-pl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110713"/>
          <criterion comment="libreoffice-langpack-es is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110495"/>
          <criterion comment="libreoffice-presentation-minimizer is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110167"/>
          <criterion comment="autocorr-fi is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110796"/>
          <criterion comment="libreoffice-langpack-mai is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110384"/>
          <criterion comment="libreoffice-langpack-nn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110446"/>
          <criterion comment="libreoffice-langpack-mr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110524"/>
          <criterion comment="libreoffice-langpack-fi is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110515"/>
          <criterion comment="libreoffice-langpack-pt-PT is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110459"/>
          <criterion comment="libreoffice-core is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110887"/>
          <criterion comment="libreoffice-impress is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110732"/>
          <criterion comment="libreoffice-langpack-ml is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110541"/>
          <criterion comment="autocorr-de is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110917"/>
          <criterion comment="libreoffice-langpack-sv is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110466"/>
          <criterion comment="libreoffice-langpack-tr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110777"/>
          <criterion comment="libreoffice-ure is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110881"/>
          <criterion comment="libreoffice-draw is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110789"/>
          <criterion comment="libreoffice-langpack-kn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110395"/>
          <criterion comment="libreoffice-langpack-ss is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110761"/>
          <criterion comment="libreoffice-langpack-nb is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110872"/>
          <criterion comment="libreoffice-ogltrans is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110826"/>
          <criterion comment="libreoffice-writer is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110867"/>
          <criterion comment="autocorr-nl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110674"/>
          <criterion comment="autocorr-bg is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110792"/>
          <criterion comment="libreoffice-langpack-as is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110552"/>
          <criterion comment="libreoffice-langpack-zh-Hant is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110585"/>
          <criterion comment="libreoffice-emailmerge is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110862"/>
          <criterion comment="libreoffice-langpack-gu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110846"/>
          <criterion comment="libreoffice-langpack-ur is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110827"/>
          <criterion comment="libreoffice-headless is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110461"/>
          <criterion comment="libreoffice-opensymbol-fonts is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110577"/>
          <criterion comment="libreoffice-sdk-doc is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110863"/>
          <criterion comment="libreoffice-langpack-da is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110932"/>
          <criterion comment="autocorr-ru is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110680"/>
          <criterion comment="libreoffice-langpack-ve is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110845"/>
          <criterion comment="libreoffice-langpack-nso is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110665"/>
          <criterion comment="libreoffice-langpack-gl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110738"/>
          <criterion comment="libreoffice-langpack-et is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110551"/>
          <criterion comment="autocorr-en is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110418"/>
          <criterion comment="libreoffice-langpack-he is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110559"/>
          <criterion comment="autocorr-sk is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110950"/>
          <criterion comment="libreoffice-langpack-nr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110647"/>
          <criterion comment="autocorr-lt is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110746"/>
          <criterion comment="libreoffice-langpack-ms is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110874"/>
          <criterion comment="autocorr-cs is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110329"/>
          <criterion comment="autocorr-pt is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110675"/>
          <criterion comment="libreoffice-langpack-dz is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110888"/>
          <criterion comment="libreoffice-langpack-en is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110797"/>
          <criterion comment="libreoffice-testtools is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110943"/>
          <criterion comment="libreoffice-gdb-debug-support is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110701"/>
          <criterion comment="libreoffice-langpack-nl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110776"/>
          <criterion comment="libreoffice-langpack-lt is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110893"/>
          <criterion comment="autocorr-fa is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110871"/>
          <criterion comment="libreoffice-langpack-pa is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110013"/>
          <criterion comment="libreoffice-wiki-publisher is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110309"/>
          <criterion comment="libreoffice-langpack-pt-BR is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110527"/>
          <criterion comment="autocorr-zh is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110311"/>
          <criterion comment="autocorr-ko is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110781"/>
          <criterion comment="libreoffice-rhino is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110111"/>
          <criterion comment="libreoffice-langpack-ts is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110594"/>
          <criterion comment="autocorr-it is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110782"/>
          <criterion comment="libreoffice-langpack-st is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110829"/>
          <criterion comment="libreoffice-langpack-ko is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110598"/>
          <criterion comment="libreoffice-sdk is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110833"/>
          <criterion comment="libreoffice-langpack-ru is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110795"/>
          <criterion comment="autocorr-hu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110865"/>
          <criterion comment="libreoffice-langpack-it is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110624"/>
          <criterion comment="libreoffice-langpack-hu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110895"/>
          <criterion comment="autocorr-lb is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110739"/>
          <criterion comment="autocorr-hr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:110753"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23712" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0685: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference ref_id="ELSA-2013:0685-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0685.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5195" ref_url="http://linux.oracle.com/cve/CVE-2012-5195.html" source="CVE"/>
        <reference ref_id="CVE-2012-5526" ref_url="http://linux.oracle.com/cve/CVE-2012-5526.html" source="CVE"/>
        <reference ref_id="CVE-2012-6329" ref_url="http://linux.oracle.com/cve/CVE-2012-6329.html" source="CVE"/>
        <reference ref_id="CVE-2013-1667" ref_url="http://linux.oracle.com/cve/CVE-2013-1667.html" source="CVE"/>
        <description>The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:49.246-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:52.538-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:54.630-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23712 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.110-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:14.404-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="perl-libs is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111851"/>
            <criterion comment="perl-suidperl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111793"/>
            <criterion comment="perl-core is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111779"/>
            <criterion comment="perl-Package-Constants is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:111945"/>
            <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-130.el6_4" test_ref="oval:org.mitre.oval:tst:111934"/>
            <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111678"/>
            <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-130.el6_4" test_ref="oval:org.mitre.oval:tst:111765"/>
            <criterion comment="perl-CGI is earlier than 0:3.51-130.el6_4" test_ref="oval:org.mitre.oval:tst:111882"/>
            <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:111830"/>
            <criterion comment="perl-Archive-Extract is earlier than 1:0.38-130.el6_4" test_ref="oval:org.mitre.oval:tst:111970"/>
            <criterion comment="perl-version is earlier than 3:0.77-130.el6_4" test_ref="oval:org.mitre.oval:tst:111359"/>
            <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-130.el6_4" test_ref="oval:org.mitre.oval:tst:111679"/>
            <criterion comment="perl-Test-Simple is earlier than 0:0.92-130.el6_4" test_ref="oval:org.mitre.oval:tst:111408"/>
            <criterion comment="perl-Compress-Raw-Zlib is earlier than 1:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111396"/>
            <criterion comment="perl-Module-Loaded is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:111753"/>
            <criterion comment="perl-IO-Compress-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111961"/>
            <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-130.el6_4" test_ref="oval:org.mitre.oval:tst:111663"/>
            <criterion comment="perl-Test-Harness is earlier than 0:3.17-130.el6_4" test_ref="oval:org.mitre.oval:tst:111941"/>
            <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:111457"/>
            <criterion comment="perl-parent is earlier than 1:0.221-130.el6_4" test_ref="oval:org.mitre.oval:tst:111771"/>
            <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111546"/>
            <criterion comment="perl-CPANPLUS is earlier than 0:0.88-130.el6_4" test_ref="oval:org.mitre.oval:tst:111933"/>
            <criterion comment="perl-Pod-Simple is earlier than 1:3.13-130.el6_4" test_ref="oval:org.mitre.oval:tst:111498"/>
            <criterion comment="perl-Module-Load is earlier than 1:0.16-130.el6_4" test_ref="oval:org.mitre.oval:tst:111974"/>
            <criterion comment="perl-File-Fetch is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:111887"/>
            <criterion comment="perl-Module-CoreList is earlier than 0:2.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:111967"/>
            <criterion comment="perl-IO-Zlib is earlier than 1:1.09-130.el6_4" test_ref="oval:org.mitre.oval:tst:111944"/>
            <criterion comment="perl-Params-Check is earlier than 1:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:111623"/>
            <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111399"/>
            <criterion comment="perl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111354"/>
            <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-130.el6_4" test_ref="oval:org.mitre.oval:tst:111656"/>
            <criterion comment="perl-Digest-SHA is earlier than 1:5.47-130.el6_4" test_ref="oval:org.mitre.oval:tst:111402"/>
            <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:111906"/>
            <criterion comment="perl-Time-Piece is earlier than 0:1.15-130.el6_4" test_ref="oval:org.mitre.oval:tst:111778"/>
            <criterion comment="perl-Archive-Tar is earlier than 0:1.58-130.el6_4" test_ref="oval:org.mitre.oval:tst:111746"/>
            <criterion comment="perl-devel is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:111907"/>
            <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-130.el6_4" test_ref="oval:org.mitre.oval:tst:111942"/>
            <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-130.el6_4" test_ref="oval:org.mitre.oval:tst:111972"/>
            <criterion comment="perl-Module-Build is earlier than 1:0.3500-130.el6_4" test_ref="oval:org.mitre.oval:tst:111875"/>
            <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-130.el6_4" test_ref="oval:org.mitre.oval:tst:111084"/>
            <criterion comment="perl-CPAN is earlier than 0:1.9402-130.el6_4" test_ref="oval:org.mitre.oval:tst:111472"/>
            <criterion comment="perl-Term-UI is earlier than 0:0.20-130.el6_4" test_ref="oval:org.mitre.oval:tst:111810"/>
            <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-130.el6_4" test_ref="oval:org.mitre.oval:tst:111966"/>
            <criterion comment="perl-Object-Accessor is earlier than 1:0.34-130.el6_4" test_ref="oval:org.mitre.oval:tst:111904"/>
            <criterion comment="perl-Compress-Raw-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:111900"/>
            <criterion comment="perl-Log-Message is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:111583"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="perl-suidperl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:111971"/>
            <criterion comment="perl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:111744"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23711" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0317: libpng security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libpng</product>
          <product>libpng10</product>
        </affected>
        <reference ref_id="ELSA-2012:0317-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0317.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3026" ref_url="http://linux.oracle.com/cve/CVE-2011-3026.html" source="CVE"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:13.988-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:52.454-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:54.478-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23711 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.647-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:14.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-static is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:110021"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:110099"/>
            <criterion comment="libpng is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:110045"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:109674"/>
            <criterion comment="libpng is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:110015"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23710" version="45" class="patch">
      <metadata>
        <title>ELSA-2012:0350: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:0350-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0350.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4077" ref_url="http://linux.oracle.com/cve/CVE-2011-4077.html" source="CVE"/>
        <reference ref_id="CVE-2011-4081" ref_url="http://linux.oracle.com/cve/CVE-2011-4081.html" source="CVE"/>
        <reference ref_id="CVE-2011-4132" ref_url="http://linux.oracle.com/cve/CVE-2011-4132.html" source="CVE"/>
        <reference ref_id="CVE-2011-4347" ref_url="http://linux.oracle.com/cve/CVE-2011-4347.html" source="CVE"/>
        <reference ref_id="CVE-2011-4594" ref_url="http://linux.oracle.com/cve/CVE-2011-4594.html" source="CVE"/>
        <reference ref_id="CVE-2011-4611" ref_url="http://linux.oracle.com/cve/CVE-2011-4611.html" source="CVE"/>
        <reference ref_id="CVE-2011-4622" ref_url="http://linux.oracle.com/cve/CVE-2011-4622.html" source="CVE"/>
        <reference ref_id="CVE-2012-0038" ref_url="http://linux.oracle.com/cve/CVE-2012-0038.html" source="CVE"/>
        <reference ref_id="CVE-2012-0045" ref_url="http://linux.oracle.com/cve/CVE-2012-0045.html" source="CVE"/>
        <reference ref_id="CVE-2012-0207" ref_url="http://linux.oracle.com/cve/CVE-2012-0207.html" source="CVE"/>
        <description>The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:08.812-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:52.120-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:54.008-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23710 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.326-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:13.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109849"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109927"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109782"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109665"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109996"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:110092"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109873"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109680"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109662"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109792"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109819"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:109778"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23709" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1459: nspluginwrapper security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nspluginwrapper</product>
        </affected>
        <reference ref_id="ELSA-2012:1459-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1459.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2486" ref_url="http://linux.oracle.com/cve/CVE-2011-2486.html" source="CVE"/>
        <description>nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:00.266-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:52.057-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:53.910-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23709 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.536-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:13.868-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="nspluginwrapper is earlier than 0:1.4.4-1.el6_3" test_ref="oval:org.mitre.oval:tst:111242"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23707" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0862: Red Hat Enterprise Linux 6 kernel security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:0862-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0862.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1083" ref_url="http://linux.oracle.com/cve/CVE-2011-1083.html" source="CVE"/>
        <reference ref_id="CVE-2011-4131" ref_url="http://linux.oracle.com/cve/CVE-2011-4131.html" source="CVE"/>
        <description>The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:42.619-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:51.954-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:53.739-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23707 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:03.180-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:13.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110358"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110521"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110546"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110368"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110482"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110427"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110235"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110184"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:109585"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110569"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110557"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:110543"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23705" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0688: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:0688-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0688.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0779" ref_url="http://linux.oracle.com/cve/CVE-2012-0779.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:39.109-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:51.822-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:53.568-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23705 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:02.820-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:13.637-04:00">ACCEPTED</status_change>
            <modified comment="duplicate of oval:org.mitre.oval:def:25131" date="2014-07-23T14:46:02.398-04:00">
              <contributor organization="Hewlett-Packard">Manu MG</contributor>
            </modified>
            <status_change date="2014-07-23T14:46:02.398-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:10.3.183.19-1.el6" test_ref="oval:org.mitre.oval:tst:109989"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23704" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0518: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openssl</product>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference ref_id="ELSA-2012:0518-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0518.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2110" ref_url="http://linux.oracle.com/cve/CVE-2012-2110.html" source="CVE"/>
        <description>The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:16.601-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:51.717-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:53.441-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23704 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:01.686-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:13.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:109721"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:109933"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:110028"/>
            <criterion comment="openssl097a is earlier than 0:0.9.7a-11.el5_8.2" test_ref="oval:org.mitre.oval:tst:109212"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:109582"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:110124"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:109820"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:110024"/>
            <criterion comment="openssl098e is earlier than 0:0.9.8e-17.el6_2.2" test_ref="oval:org.mitre.oval:tst:109295"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23703" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0433: xorg-x11-server-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xorg-x11-server-utils</product>
        </affected>
        <reference ref_id="ELSA-2011:0433-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0433.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0465" ref_url="http://linux.oracle.com/cve/CVE-2011-0465.html" source="CVE"/>
        <description>xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:27.577-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:51.642-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:53.342-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23703 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:04.638-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:13.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="xorg-x11-server-utils is earlier than 0:7.4-15.el6_0.1" test_ref="oval:org.mitre.oval:tst:108743"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23702" version="65" class="patch">
      <metadata>
        <title>ELSA-2011:0471: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:0471-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0471.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0065" ref_url="http://linux.oracle.com/cve/CVE-2011-0065.html" source="CVE"/>
        <reference ref_id="CVE-2011-0066" ref_url="http://linux.oracle.com/cve/CVE-2011-0066.html" source="CVE"/>
        <reference ref_id="CVE-2011-0067" ref_url="http://linux.oracle.com/cve/CVE-2011-0067.html" source="CVE"/>
        <reference ref_id="CVE-2011-0069" ref_url="http://linux.oracle.com/cve/CVE-2011-0069.html" source="CVE"/>
        <reference ref_id="CVE-2011-0070" ref_url="http://linux.oracle.com/cve/CVE-2011-0070.html" source="CVE"/>
        <reference ref_id="CVE-2011-0071" ref_url="http://linux.oracle.com/cve/CVE-2011-0071.html" source="CVE"/>
        <reference ref_id="CVE-2011-0072" ref_url="http://linux.oracle.com/cve/CVE-2011-0072.html" source="CVE"/>
        <reference ref_id="CVE-2011-0073" ref_url="http://linux.oracle.com/cve/CVE-2011-0073.html" source="CVE"/>
        <reference ref_id="CVE-2011-0074" ref_url="http://linux.oracle.com/cve/CVE-2011-0074.html" source="CVE"/>
        <reference ref_id="CVE-2011-0075" ref_url="http://linux.oracle.com/cve/CVE-2011-0075.html" source="CVE"/>
        <reference ref_id="CVE-2011-0077" ref_url="http://linux.oracle.com/cve/CVE-2011-0077.html" source="CVE"/>
        <reference ref_id="CVE-2011-0078" ref_url="http://linux.oracle.com/cve/CVE-2011-0078.html" source="CVE"/>
        <reference ref_id="CVE-2011-0080" ref_url="http://linux.oracle.com/cve/CVE-2011-0080.html" source="CVE"/>
        <reference ref_id="CVE-2011-0081" ref_url="http://linux.oracle.com/cve/CVE-2011-0081.html" source="CVE"/>
        <reference ref_id="CVE-2011-1202" ref_url="http://linux.oracle.com/cve/CVE-2011-1202.html" source="CVE"/>
        <description>The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:34.378-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:51.226-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:52.698-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23702 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.495-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:13.029-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="firefox is earlier than 0:3.6.17-1.el6_0" test_ref="oval:org.mitre.oval:tst:108829"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.17-4.el6_0" test_ref="oval:org.mitre.oval:tst:108469"/>
          <criterion comment="xulrunner is earlier than 0:1.9.2.17-4.el6_0" test_ref="oval:org.mitre.oval:tst:108112"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23701" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0858: xerces-j2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>xerces-j2</product>
        </affected>
        <reference ref_id="ELSA-2011:0858-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0858.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-2625" ref_url="http://linux.oracle.com/cve/CVE-2009-2625.html" source="CVE"/>
        <description>XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:21.590-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:51.134-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:52.565-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23701 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:01.980-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:12.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:108734"/>
          <criterion comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:108897"/>
          <criterion comment="xerces-j2-demo is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:108904"/>
          <criterion comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:109028"/>
          <criterion comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:108663"/>
          <criterion comment="xerces-j2 is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:108920"/>
          <criterion comment="xerces-j2-scripts is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:109060"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23698" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0731: expat security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>expat</product>
        </affected>
        <reference ref_id="ELSA-2012:0731-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0731.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0876" ref_url="http://linux.oracle.com/cve/CVE-2012-0876.html" source="CVE"/>
        <reference ref_id="CVE-2012-1148" ref_url="http://linux.oracle.com/cve/CVE-2012-1148.html" source="CVE"/>
        <description>Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:41.331-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:51.024-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:52.023-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23698 - optimisation of Oracle Linux content" date="2014-05-05T17:27:00.179-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:30:00.374-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:12.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="expat-devel is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:109508"/>
            <criterion comment="expat is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:110102"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="expat-devel is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:109583"/>
            <criterion comment="expat is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:110502"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23697" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1356: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2011:1356-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1356.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3380" ref_url="http://linux.oracle.com/cve/CVE-2011-3380.html" source="CVE"/>
        <description>Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:57.592-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:50.935-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:51.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23697 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:26.263-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:01.352-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.2" test_ref="oval:org.mitre.oval:tst:109334"/>
          <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.2" test_ref="oval:org.mitre.oval:tst:109332"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23694" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0011: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2012:0011-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0011.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2462" ref_url="http://linux.oracle.com/cve/CVE-2011-2462.html" source="CVE"/>
        <reference ref_id="CVE-2011-4369" ref_url="http://linux.oracle.com/cve/CVE-2011-4369.html" source="CVE"/>
        <description>Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:08.549-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:50.532-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:51.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23694 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:25.233-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:12.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:109271"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:109602"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.7-1.el6" test_ref="oval:org.mitre.oval:tst:109590"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.7-1.el6" test_ref="oval:org.mitre.oval:tst:109216"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23692" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1156: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1156-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1156.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1078" ref_url="http://linux.oracle.com/cve/CVE-2011-1078.html" source="CVE"/>
        <reference ref_id="CVE-2012-2383" ref_url="http://linux.oracle.com/cve/CVE-2012-2383.html" source="CVE"/>
        <description>Integer overflow in the i915_gem_execbuffer2 function in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.3.5 on 32-bit platforms allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted ioctl call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:50.851-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:50.215-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:51.310-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23692 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:25.630-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:12.493-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110612"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110605"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110912"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110765"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110673"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110441"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110804"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110944"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110839"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110403"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110225"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:110790"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23690" version="9" class="patch">
      <metadata>
        <title>ELSA-2014:0328: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2014:0328-01" ref_url="http://linux.oracle.com/errata/ELSA-2014-0328.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1860" ref_url="http://linux.oracle.com/cve/CVE-2013-1860.html" source="CVE"/>
        <reference ref_id="CVE-2014-0055" ref_url="http://linux.oracle.com/cve/CVE-2014-0055.html" source="CVE"/>
        <reference ref_id="CVE-2014-0069" ref_url="http://linux.oracle.com/cve/CVE-2014-0069.html" source="CVE"/>
        <reference ref_id="CVE-2014-0101" ref_url="http://linux.oracle.com/cve/CVE-2014-0101.html" source="CVE"/>
        <description>The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:26.949-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:05:51.052-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:07.909-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23690 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:30.781-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:00.991-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113770"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113610"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113359"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113765"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113109"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113121"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113788"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113775"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113708"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113687"/>
          <criterion comment="kernel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113468"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113711"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113698"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23689" version="21" class="patch">
      <metadata>
        <title>ELSA-2011:0839: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference ref_id="ELSA-2011:0839-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0839.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4540" ref_url="http://linux.oracle.com/cve/CVE-2010-4540.html" source="CVE"/>
        <reference ref_id="CVE-2010-4541" ref_url="http://linux.oracle.com/cve/CVE-2010-4541.html" source="CVE"/>
        <reference ref_id="CVE-2010-4542" ref_url="http://linux.oracle.com/cve/CVE-2010-4542.html" source="CVE"/>
        <reference ref_id="CVE-2010-4543" ref_url="http://linux.oracle.com/cve/CVE-2010-4543.html" source="CVE"/>
        <description>Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image.	 NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:30.493-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:50.080-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:50.827-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23689 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:23.719-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:12.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gimp-libs is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:108751"/>
          <criterion comment="gimp-devel is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:109016"/>
          <criterion comment="gimp-help-browser is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:108716"/>
          <criterion comment="gimp is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:108842"/>
          <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:108900"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23688" version="41" class="patch">
      <metadata>
        <title>ELSA-2012:1238: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2012:1238-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1238.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0551" ref_url="http://linux.oracle.com/cve/CVE-2012-0551.html" source="CVE"/>
        <reference ref_id="CVE-2012-1713" ref_url="http://linux.oracle.com/cve/CVE-2012-1713.html" source="CVE"/>
        <reference ref_id="CVE-2012-1716" ref_url="http://linux.oracle.com/cve/CVE-2012-1716.html" source="CVE"/>
        <reference ref_id="CVE-2012-1717" ref_url="http://linux.oracle.com/cve/CVE-2012-1717.html" source="CVE"/>
        <reference ref_id="CVE-2012-1718" ref_url="http://linux.oracle.com/cve/CVE-2012-1718.html" source="CVE"/>
        <reference ref_id="CVE-2012-1719" ref_url="http://linux.oracle.com/cve/CVE-2012-1719.html" source="CVE"/>
        <reference ref_id="CVE-2012-1721" ref_url="http://linux.oracle.com/cve/CVE-2012-1721.html" source="CVE"/>
        <reference ref_id="CVE-2012-1722" ref_url="http://linux.oracle.com/cve/CVE-2012-1722.html" source="CVE"/>
        <reference ref_id="CVE-2012-1725" ref_url="http://linux.oracle.com/cve/CVE-2012-1725.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:54.381-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:49.860-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:50.412-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23688 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.449-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:12.028-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110800"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110891"/>
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111105"/>
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110646"/>
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110280"/>
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110971"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110835"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23687" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0270: jakarta-commons-httpclient security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference ref_id="ELSA-2013:0270-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0270.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5783" ref_url="http://linux.oracle.com/cve/CVE-2012-5783.html" source="CVE"/>
        <description>Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:27.395-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:49.776-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:50.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23687 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:23.606-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:11.907-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:111410"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:111388"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:110947"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:111284"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:111463"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:111101"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:110903"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:111073"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23686" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:1164: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:1164-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1164.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0084" ref_url="http://linux.oracle.com/cve/CVE-2011-0084.html" source="CVE"/>
        <reference ref_id="CVE-2011-2378" ref_url="http://linux.oracle.com/cve/CVE-2011-2378.html" source="CVE"/>
        <reference ref_id="CVE-2011-2981" ref_url="http://linux.oracle.com/cve/CVE-2011-2981.html" source="CVE"/>
        <reference ref_id="CVE-2011-2982" ref_url="http://linux.oracle.com/cve/CVE-2011-2982.html" source="CVE"/>
        <reference ref_id="CVE-2011-2983" ref_url="http://linux.oracle.com/cve/CVE-2011-2983.html" source="CVE"/>
        <reference ref_id="CVE-2011-2984" ref_url="http://linux.oracle.com/cve/CVE-2011-2984.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:21.826-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:49.592-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:49.937-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23686 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.901-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:11.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:109163"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:109104"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el5" test_ref="oval:org.mitre.oval:tst:109261"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:109066"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:108664"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:109096"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23685" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0395: gdm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gdm</product>
        </affected>
        <reference ref_id="ELSA-2011:0395-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0395.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0727" ref_url="http://linux.oracle.com/cve/CVE-2011-0727.html" source="CVE"/>
        <description>GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:42.531-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:49.518-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:49.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23685 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.994-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:11.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gdm-user-switch-applet is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:108758"/>
          <criterion comment="gdm-plugin-smartcard is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:108721"/>
          <criterion comment="gdm is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:108571"/>
          <criterion comment="gdm-plugin-fingerprint is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:108700"/>
          <criterion comment="gdm-libs is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:108577"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23684" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1458: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2011:1458-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1458.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4313" ref_url="http://linux.oracle.com/cve/CVE-2011-4313.html" source="CVE"/>
        <description>query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:09.393-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:49.430-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:49.688-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23684 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.712-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:11.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109676"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109550"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109294"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109548"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109705"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109539"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109528"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:109642"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109385"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109719"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109573"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109682"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109546"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:109596"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23683" version="77" class="patch">
      <metadata>
        <title>ELSA-2012:0105: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2012:0105-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0105.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2262" ref_url="http://linux.oracle.com/cve/CVE-2011-2262.html" source="CVE"/>
        <reference ref_id="CVE-2012-0075" ref_url="http://linux.oracle.com/cve/CVE-2012-0075.html" source="CVE"/>
        <reference ref_id="CVE-2012-0087" ref_url="http://linux.oracle.com/cve/CVE-2012-0087.html" source="CVE"/>
        <reference ref_id="CVE-2012-0101" ref_url="http://linux.oracle.com/cve/CVE-2012-0101.html" source="CVE"/>
        <reference ref_id="CVE-2012-0102" ref_url="http://linux.oracle.com/cve/CVE-2012-0102.html" source="CVE"/>
        <reference ref_id="CVE-2012-0112" ref_url="http://linux.oracle.com/cve/CVE-2012-0112.html" source="CVE"/>
        <reference ref_id="CVE-2012-0113" ref_url="http://linux.oracle.com/cve/CVE-2012-0113.html" source="CVE"/>
        <reference ref_id="CVE-2012-0114" ref_url="http://linux.oracle.com/cve/CVE-2012-0114.html" source="CVE"/>
        <reference ref_id="CVE-2012-0115" ref_url="http://linux.oracle.com/cve/CVE-2012-0115.html" source="CVE"/>
        <reference ref_id="CVE-2012-0116" ref_url="http://linux.oracle.com/cve/CVE-2012-0116.html" source="CVE"/>
        <reference ref_id="CVE-2012-0118" ref_url="http://linux.oracle.com/cve/CVE-2012-0118.html" source="CVE"/>
        <reference ref_id="CVE-2012-0119" ref_url="http://linux.oracle.com/cve/CVE-2012-0119.html" source="CVE"/>
        <reference ref_id="CVE-2012-0120" ref_url="http://linux.oracle.com/cve/CVE-2012-0120.html" source="CVE"/>
        <reference ref_id="CVE-2012-0484" ref_url="http://linux.oracle.com/cve/CVE-2012-0484.html" source="CVE"/>
        <reference ref_id="CVE-2012-0485" ref_url="http://linux.oracle.com/cve/CVE-2012-0485.html" source="CVE"/>
        <reference ref_id="CVE-2012-0490" ref_url="http://linux.oracle.com/cve/CVE-2012-0490.html" source="CVE"/>
        <reference ref_id="CVE-2012-0492" ref_url="http://linux.oracle.com/cve/CVE-2012-0492.html" source="CVE"/>
        <reference ref_id="CVE-2012-0583" ref_url="http://linux.oracle.com/cve/CVE-2012-0583.html" source="CVE"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:04.430-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:49.016-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:48.850-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23683 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:23.989-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:10.979-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-server is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:109815"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:110014"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:109880"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:109804"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:110039"/>
          <criterion comment="mysql-test is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:110097"/>
          <criterion comment="mysql is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:109800"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:109812"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23682" version="65" class="patch">
      <metadata>
        <title>ELSA-2011:0542: Red Hat Enterprise Linux 6.1 kernel security, bug fix and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0542-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0542.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3881" ref_url="http://linux.oracle.com/cve/CVE-2010-3881.html" source="CVE"/>
        <reference ref_id="CVE-2010-4251" ref_url="http://linux.oracle.com/cve/CVE-2010-4251.html" source="CVE"/>
        <reference ref_id="CVE-2010-4805" ref_url="http://linux.oracle.com/cve/CVE-2010-4805.html" source="CVE"/>
        <reference ref_id="CVE-2011-0999" ref_url="http://linux.oracle.com/cve/CVE-2011-0999.html" source="CVE"/>
        <reference ref_id="CVE-2011-1010" ref_url="http://linux.oracle.com/cve/CVE-2011-1010.html" source="CVE"/>
        <reference ref_id="CVE-2011-1023" ref_url="http://linux.oracle.com/cve/CVE-2011-1023.html" source="CVE"/>
        <reference ref_id="CVE-2011-1082" ref_url="http://linux.oracle.com/cve/CVE-2011-1082.html" source="CVE"/>
        <reference ref_id="CVE-2011-1090" ref_url="http://linux.oracle.com/cve/CVE-2011-1090.html" source="CVE"/>
        <reference ref_id="CVE-2011-1163" ref_url="http://linux.oracle.com/cve/CVE-2011-1163.html" source="CVE"/>
        <reference ref_id="CVE-2011-1170" ref_url="http://linux.oracle.com/cve/CVE-2011-1170.html" source="CVE"/>
        <reference ref_id="CVE-2011-1171" ref_url="http://linux.oracle.com/cve/CVE-2011-1171.html" source="CVE"/>
        <reference ref_id="CVE-2011-1172" ref_url="http://linux.oracle.com/cve/CVE-2011-1172.html" source="CVE"/>
        <reference ref_id="CVE-2011-1494" ref_url="http://linux.oracle.com/cve/CVE-2011-1494.html" source="CVE"/>
        <reference ref_id="CVE-2011-1495" ref_url="http://linux.oracle.com/cve/CVE-2011-1495.html" source="CVE"/>
        <reference ref_id="CVE-2011-1581" ref_url="http://linux.oracle.com/cve/CVE-2011-1581.html" source="CVE"/>
        <description>The bond_select_queue function in drivers/net/bonding/bond_main.c in the Linux kernel before 2.6.39, when a network device with a large number of receive queues is installed but the default tx_queues setting is used, does not properly restrict queue indexes, which allows remote attackers to cause a denial of service (BUG and system crash) or possibly have unspecified other impact by sending network traffic.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:30.053-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:48.661-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:48.209-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23682 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:24.290-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:10.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108843"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108594"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108929"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108270"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108917"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108800"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108923"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108737"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108913"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108774"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:108689"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23681" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0199: libvirt security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2013:0199-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0199.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0170" ref_url="http://linux.oracle.com/cve/CVE-2013-0170.html" source="CVE"/>
        <description>Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:26.767-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:48.581-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:48.093-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23681 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.898-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:10.480-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:111132"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:111363"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:111214"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:110923"/>
          <criterion comment="libvirt is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:111296"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23680" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0656: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2013:0656-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0656.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1016" ref_url="http://linux.oracle.com/cve/CVE-2012-1016.html" source="CVE"/>
        <reference ref_id="CVE-2013-1415" ref_url="http://linux.oracle.com/cve/CVE-2013-1415.html" source="CVE"/>
        <description>The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_openssl.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 and 1.11.x before 1.11.1 does not properly handle errors during extraction of fields from an X.509 certificate, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed KRB5_PADATA_PK_AS_REQ AS-REQ request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:40.629-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:48.493-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:47.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23680 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:24.444-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:10.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111660"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111853"/>
          <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111423"/>
          <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111845"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111840"/>
          <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111723"/>
          <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:111768"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23679" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1807: jasper security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>jasper</product>
        </affected>
        <reference ref_id="ELSA-2011:1807-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1807.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4516" ref_url="http://linux.oracle.com/cve/CVE-2011-4516.html" source="CVE"/>
        <reference ref_id="CVE-2011-4517" ref_url="http://linux.oracle.com/cve/CVE-2011-4517.html" source="CVE"/>
        <description>The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:09.768-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:48.413-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:47.802-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23679 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:24.945-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:10.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="jasper is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:109580"/>
          <criterion comment="jasper-utils is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:109514"/>
          <criterion comment="jasper-devel is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:109581"/>
          <criterion comment="jasper-libs is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:109521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23678" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1549: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:1549-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1549.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5688" ref_url="http://linux.oracle.com/cve/CVE-2012-5688.html" source="CVE"/>
        <description>ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:10.683-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:48.344-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:47.680-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23678 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.393-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:10.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:111017"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:111291"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:111046"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:111083"/>
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:110759"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:111187"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23677" version="53" class="patch">
      <metadata>
        <title>ELSA-2011:1465: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:1465-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1465.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1162" ref_url="http://linux.oracle.com/cve/CVE-2011-1162.html" source="CVE"/>
        <reference ref_id="CVE-2011-1577" ref_url="http://linux.oracle.com/cve/CVE-2011-1577.html" source="CVE"/>
        <reference ref_id="CVE-2011-2494" ref_url="http://linux.oracle.com/cve/CVE-2011-2494.html" source="CVE"/>
        <reference ref_id="CVE-2011-2699" ref_url="http://linux.oracle.com/cve/CVE-2011-2699.html" source="CVE"/>
        <reference ref_id="CVE-2011-2905" ref_url="http://linux.oracle.com/cve/CVE-2011-2905.html" source="CVE"/>
        <reference ref_id="CVE-2011-3188" ref_url="http://linux.oracle.com/cve/CVE-2011-3188.html" source="CVE"/>
        <reference ref_id="CVE-2011-3191" ref_url="http://linux.oracle.com/cve/CVE-2011-3191.html" source="CVE"/>
        <reference ref_id="CVE-2011-3353" ref_url="http://linux.oracle.com/cve/CVE-2011-3353.html" source="CVE"/>
        <reference ref_id="CVE-2011-3359" ref_url="http://linux.oracle.com/cve/CVE-2011-3359.html" source="CVE"/>
        <reference ref_id="CVE-2011-3363" ref_url="http://linux.oracle.com/cve/CVE-2011-3363.html" source="CVE"/>
        <reference ref_id="CVE-2011-3593" ref_url="http://linux.oracle.com/cve/CVE-2011-3593.html" source="CVE"/>
        <reference ref_id="CVE-2011-4326" ref_url="http://linux.oracle.com/cve/CVE-2011-4326.html" source="CVE"/>
        <description>The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:02.268-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:48.069-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:47.147-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23677 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:25.364-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:09.834-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109230"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109486"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109452"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109554"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109557"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109299"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109383"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109567"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109153"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109142"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:109678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23676" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0699: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2012:0699-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0699.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2333" ref_url="http://linux.oracle.com/cve/CVE-2012-2333.html" source="CVE"/>
        <description>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:22.045-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:47.993-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:47.009-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23676 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.709-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:09.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:110216"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:110245"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:110148"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:110203"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:110048"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:109855"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:109777"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23675" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1197: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2011:1197-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1197.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2511" ref_url="http://linux.oracle.com/cve/CVE-2011-2511.html" source="CVE"/>
        <description>Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:12.443-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:47.893-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:46.894-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23675 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.078-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:09.624-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.8.7-18.el6_1.1" test_ref="oval:org.mitre.oval:tst:109245"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.7-18.el6_1.1" test_ref="oval:org.mitre.oval:tst:109250"/>
          <criterion comment="libvirt-client is earlier than 0:0.8.7-18.el6_1.1" test_ref="oval:org.mitre.oval:tst:109256"/>
          <criterion comment="libvirt is earlier than 0:0.8.7-18.el6_1.1" test_ref="oval:org.mitre.oval:tst:109194"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23674" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0897: mesa security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mesa</product>
        </affected>
        <reference ref_id="ELSA-2013:0897-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0897.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1872" ref_url="http://linux.oracle.com/cve/CVE-2013-1872.html" source="CVE"/>
        <reference ref_id="CVE-2013-1993" ref_url="http://linux.oracle.com/cve/CVE-2013-1993.html" source="CVE"/>
        <description>Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:13.747-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:47.798-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:46.725-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23674 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:24.834-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:09.498-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mesa-libGL-devel is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:111558"/>
          <criterion comment="glx-utils is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:111955"/>
          <criterion comment="mesa-dri-drivers is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:112128"/>
          <criterion comment="mesa is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:112126"/>
          <criterion comment="mesa-libGLU is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:111935"/>
          <criterion comment="mesa-dri-filesystem is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:111936"/>
          <criterion comment="mesa-libGL is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:111915"/>
          <criterion comment="mesa-demos is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:112108"/>
          <criterion comment="mesa-libGLU-devel is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:111176"/>
          <criterion comment="mesa-libOSMesa-devel is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:111714"/>
          <criterion comment="mesa-libOSMesa is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:111948"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23673" version="137" class="patch">
      <metadata>
        <title>ELSA-2013:0625: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:0625-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0625.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1541" ref_url="http://linux.oracle.com/cve/CVE-2012-1541.html" source="CVE"/>
        <reference ref_id="CVE-2012-3213" ref_url="http://linux.oracle.com/cve/CVE-2012-3213.html" source="CVE"/>
        <reference ref_id="CVE-2012-3342" ref_url="http://linux.oracle.com/cve/CVE-2012-3342.html" source="CVE"/>
        <reference ref_id="CVE-2012-5085" ref_url="http://linux.oracle.com/cve/CVE-2012-5085.html" source="CVE"/>
        <reference ref_id="CVE-2013-0351" ref_url="http://linux.oracle.com/cve/CVE-2013-0351.html" source="CVE"/>
        <reference ref_id="CVE-2013-0409" ref_url="http://linux.oracle.com/cve/CVE-2013-0409.html" source="CVE"/>
        <reference ref_id="CVE-2013-0419" ref_url="http://linux.oracle.com/cve/CVE-2013-0419.html" source="CVE"/>
        <reference ref_id="CVE-2013-0423" ref_url="http://linux.oracle.com/cve/CVE-2013-0423.html" source="CVE"/>
        <reference ref_id="CVE-2013-0424" ref_url="http://linux.oracle.com/cve/CVE-2013-0424.html" source="CVE"/>
        <reference ref_id="CVE-2013-0425" ref_url="http://linux.oracle.com/cve/CVE-2013-0425.html" source="CVE"/>
        <reference ref_id="CVE-2013-0426" ref_url="http://linux.oracle.com/cve/CVE-2013-0426.html" source="CVE"/>
        <reference ref_id="CVE-2013-0427" ref_url="http://linux.oracle.com/cve/CVE-2013-0427.html" source="CVE"/>
        <reference ref_id="CVE-2013-0428" ref_url="http://linux.oracle.com/cve/CVE-2013-0428.html" source="CVE"/>
        <reference ref_id="CVE-2013-0432" ref_url="http://linux.oracle.com/cve/CVE-2013-0432.html" source="CVE"/>
        <reference ref_id="CVE-2013-0433" ref_url="http://linux.oracle.com/cve/CVE-2013-0433.html" source="CVE"/>
        <reference ref_id="CVE-2013-0434" ref_url="http://linux.oracle.com/cve/CVE-2013-0434.html" source="CVE"/>
        <reference ref_id="CVE-2013-0435" ref_url="http://linux.oracle.com/cve/CVE-2013-0435.html" source="CVE"/>
        <reference ref_id="CVE-2013-0438" ref_url="http://linux.oracle.com/cve/CVE-2013-0438.html" source="CVE"/>
        <reference ref_id="CVE-2013-0440" ref_url="http://linux.oracle.com/cve/CVE-2013-0440.html" source="CVE"/>
        <reference ref_id="CVE-2013-0441" ref_url="http://linux.oracle.com/cve/CVE-2013-0441.html" source="CVE"/>
        <reference ref_id="CVE-2013-0442" ref_url="http://linux.oracle.com/cve/CVE-2013-0442.html" source="CVE"/>
        <reference ref_id="CVE-2013-0443" ref_url="http://linux.oracle.com/cve/CVE-2013-0443.html" source="CVE"/>
        <reference ref_id="CVE-2013-0445" ref_url="http://linux.oracle.com/cve/CVE-2013-0445.html" source="CVE"/>
        <reference ref_id="CVE-2013-0446" ref_url="http://linux.oracle.com/cve/CVE-2013-0446.html" source="CVE"/>
        <reference ref_id="CVE-2013-0450" ref_url="http://linux.oracle.com/cve/CVE-2013-0450.html" source="CVE"/>
        <reference ref_id="CVE-2013-0809" ref_url="http://linux.oracle.com/cve/CVE-2013-0809.html" source="CVE"/>
        <reference ref_id="CVE-2013-1473" ref_url="http://linux.oracle.com/cve/CVE-2013-1473.html" source="CVE"/>
        <reference ref_id="CVE-2013-1476" ref_url="http://linux.oracle.com/cve/CVE-2013-1476.html" source="CVE"/>
        <reference ref_id="CVE-2013-1478" ref_url="http://linux.oracle.com/cve/CVE-2013-1478.html" source="CVE"/>
        <reference ref_id="CVE-2013-1480" ref_url="http://linux.oracle.com/cve/CVE-2013-1480.html" source="CVE"/>
        <reference ref_id="CVE-2013-1481" ref_url="http://linux.oracle.com/cve/CVE-2013-1481.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <reference ref_id="CVE-2013-1487" ref_url="http://linux.oracle.com/cve/CVE-2013-1487.html" source="CVE"/>
        <reference ref_id="CVE-2013-1493" ref_url="http://linux.oracle.com/cve/CVE-2013-1493.html" source="CVE"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:37.964-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:47.065-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:45.343-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23673 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.067-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:111811"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:111821"/>
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:111762"/>
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:110848"/>
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:111705"/>
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:110934"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:111683"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23672" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1790: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2011:1790-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1790.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1530" ref_url="http://linux.oracle.com/cve/CVE-2011-1530.html" source="CVE"/>
        <description>The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:14.160-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.987-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:45.110-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23672 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:24.140-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.630-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-devel is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:109240"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:109463"/>
          <criterion comment="krb5-workstation is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:109519"/>
          <criterion comment="krb5-libs is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:109335"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:109018"/>
          <criterion comment="krb5-server is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:109172"/>
          <criterion comment="krb5 is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:109675"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23671" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0434: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:0434-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0434.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0773" ref_url="http://linux.oracle.com/cve/CVE-2012-0773.html" source="CVE"/>
        <description>The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:19.079-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.921-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:44.903-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23671 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.816-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.535-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el5" test_ref="oval:org.mitre.oval:tst:110131"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el6" test_ref="oval:org.mitre.oval:tst:109892"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23669" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:0481: kernel security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:0481-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0481.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0879" ref_url="http://linux.oracle.com/cve/CVE-2012-0879.html" source="CVE"/>
        <reference ref_id="CVE-2012-1090" ref_url="http://linux.oracle.com/cve/CVE-2012-1090.html" source="CVE"/>
        <reference ref_id="CVE-2012-1097" ref_url="http://linux.oracle.com/cve/CVE-2012-1097.html" source="CVE"/>
        <description>The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:34.753-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.748-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:44.515-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23669 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:25.515-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:109755"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:110057"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:109450"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:109906"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:110017"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:109598"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:110150"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:109870"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:109944"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:109992"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:109754"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:110047"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23668" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0669: qt security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference ref_id="ELSA-2013:0669-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0669.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0254" ref_url="http://linux.oracle.com/cve/CVE-2013-0254.html" source="CVE"/>
        <description>The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:53.784-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.623-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:44.374-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23668 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.263-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.280-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qt-demos is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111616"/>
          <criterion comment="qt-odbc is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:110979"/>
          <criterion comment="qt-mysql is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111969"/>
          <criterion comment="qt-x11 is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111471"/>
          <criterion comment="qt-doc is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111876"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111859"/>
          <criterion comment="qt-sqlite is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111107"/>
          <criterion comment="qt-postgresql is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111611"/>
          <criterion comment="qt is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111672"/>
          <criterion comment="qt-devel is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111940"/>
          <criterion comment="qt-examples is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:111890"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23667" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:0472: nss security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2011:0472-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0472.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.
This erratum blacklists a small number of HTTPS certificates by adding
them, flagged as untrusted, to the NSS Builtin Object Token (the
libnssckbi.so library) certificate store. (BZ#689430)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not blacklist the certificates for applications that use the
NSS library, but do not use the NSS Builtin Object Token (such as curl).
All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:31.748-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.515-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:44.290-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23667 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:23.394-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.206-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="nss-tools is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:108781"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:108684"/>
          <criterion comment="nss-sysinit is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:108762"/>
          <criterion comment="nss is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:108752"/>
          <criterion comment="nss-devel is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:108814"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23665" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0843: postfix security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>postfix</product>
        </affected>
        <reference ref_id="ELSA-2011:0843-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0843.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1720" ref_url="http://linux.oracle.com/cve/CVE-2011-1720.html" source="CVE"/>
        <description>The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:42.997-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.418-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:44.179-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23665 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:25.131-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postfix-perl-scripts is earlier than 2:2.6.6-2.2.el6_1" test_ref="oval:org.mitre.oval:tst:108972"/>
          <criterion comment="postfix is earlier than 2:2.6.6-2.2.el6_1" test_ref="oval:org.mitre.oval:tst:108862"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23664" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:1333: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1333-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1333.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2426" ref_url="http://linux.oracle.com/cve/CVE-2011-2426.html" source="CVE"/>
        <reference ref_id="CVE-2011-2427" ref_url="http://linux.oracle.com/cve/CVE-2011-2427.html" source="CVE"/>
        <reference ref_id="CVE-2011-2428" ref_url="http://linux.oracle.com/cve/CVE-2011-2428.html" source="CVE"/>
        <reference ref_id="CVE-2011-2429" ref_url="http://linux.oracle.com/cve/CVE-2011-2429.html" source="CVE"/>
        <reference ref_id="CVE-2011-2430" ref_url="http://linux.oracle.com/cve/CVE-2011-2430.html" source="CVE"/>
        <reference ref_id="CVE-2011-2444" ref_url="http://linux.oracle.com/cve/CVE-2011-2444.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:08.423-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.279-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:44.099-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23664 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.494-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:08.039-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el5" test_ref="oval:org.mitre.oval:tst:109320"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el6" test_ref="oval:org.mitre.oval:tst:109313"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23663" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0884: openssh security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference ref_id="ELSA-2012:0884-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0884.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-5000" ref_url="http://linux.oracle.com/cve/CVE-2011-5000.html" source="CVE"/>
        <description>The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field.	 NOTE: there may be limited scenarios in which this issue is relevant.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:23.689-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.174-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:43.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23663 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:25.736-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:07.945-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssh-askpass is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:110272"/>
          <criterion comment="openssh-server is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:110199"/>
          <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9-81.el6" test_ref="oval:org.mitre.oval:tst:110494"/>
          <criterion comment="openssh-clients is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:110022"/>
          <criterion comment="openssh-ldap is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:110220"/>
          <criterion comment="openssh is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:109650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23662" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1269: qpid security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python-qpid</product>
          <product>qpid-cpp</product>
          <product>qpid-qmf</product>
          <product>qpid-tools</product>
        </affected>
        <reference ref_id="ELSA-2012:1269-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1269.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2145" ref_url="http://linux.oracle.com/cve/CVE-2012-2145.html" source="CVE"/>
        <description>Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:01.089-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:46.060-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:43.826-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23662 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:25.867-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:07.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="python-qpid is earlier than 0:0.14-11.el6_3" test_ref="oval:org.mitre.oval:tst:110904"/>
          <criterion comment="ruby-qpid-qmf is earlier than 0:0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:110638"/>
          <criterion comment="qpid-qmf-devel is earlier than 0:0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:111171"/>
          <criterion comment="qpid-qmf is earlier than 0:0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:111097"/>
          <criterion comment="python-qpid-qmf is earlier than 0:0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:110514"/>
          <criterion comment="qpid-tools is earlier than 0:0.14-6.el6_3" test_ref="oval:org.mitre.oval:tst:111099"/>
          <criterion comment="qpid-cpp-client-devel is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111130"/>
          <criterion comment="qpid-cpp-server-devel is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111007"/>
          <criterion comment="qpid-cpp-client-rdma is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111011"/>
          <criterion comment="qpid-cpp-client-ssl is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111197"/>
          <criterion comment="qpid-cpp-server-cluster is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111033"/>
          <criterion comment="qpid-cpp is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111191"/>
          <criterion comment="qpid-cpp-server is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111109"/>
          <criterion comment="qpid-cpp-server-ssl is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:110928"/>
          <criterion comment="rh-qpid-cpp-tests is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111116"/>
          <criterion comment="qpid-cpp-client is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111190"/>
          <criterion comment="qpid-cpp-server-xml is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:110855"/>
          <criterion comment="qpid-cpp-client-devel-docs is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111091"/>
          <criterion comment="qpid-cpp-server-rdma is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:110914"/>
          <criterion comment="qpid-cpp-server-store is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:111041"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23661" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0586: libguestfs security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libguestfs</product>
        </affected>
        <reference ref_id="ELSA-2011:0586-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0586.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3851" ref_url="http://linux.oracle.com/cve/CVE-2010-3851.html" source="CVE"/>
        <description>libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:29.081-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:45.968-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:43.686-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23661 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:28.879-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:07.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libguestfs-java-devel is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108941"/>
          <criterion comment="libguestfs-java is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108491"/>
          <criterion comment="libguestfs-javadoc is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108456"/>
          <criterion comment="perl-Sys-Guestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108985"/>
          <criterion comment="libguestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108995"/>
          <criterion comment="ocaml-libguestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108673"/>
          <criterion comment="libguestfs-mount is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108925"/>
          <criterion comment="python-libguestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108811"/>
          <criterion comment="ocaml-libguestfs-devel is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108872"/>
          <criterion comment="libguestfs-devel is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108760"/>
          <criterion comment="libguestfs-tools-c is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108468"/>
          <criterion comment="ruby-libguestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108910"/>
          <criterion comment="guestfish is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108496"/>
          <criterion comment="libguestfs-tools is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:108863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23660" version="53" class="patch">
      <metadata>
        <title>ELSA-2012:0516: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0516-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0516.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3062" ref_url="http://linux.oracle.com/cve/CVE-2011-3062.html" source="CVE"/>
        <reference ref_id="CVE-2012-0467" ref_url="http://linux.oracle.com/cve/CVE-2012-0467.html" source="CVE"/>
        <reference ref_id="CVE-2012-0468" ref_url="http://linux.oracle.com/cve/CVE-2012-0468.html" source="CVE"/>
        <reference ref_id="CVE-2012-0469" ref_url="http://linux.oracle.com/cve/CVE-2012-0469.html" source="CVE"/>
        <reference ref_id="CVE-2012-0470" ref_url="http://linux.oracle.com/cve/CVE-2012-0470.html" source="CVE"/>
        <reference ref_id="CVE-2012-0471" ref_url="http://linux.oracle.com/cve/CVE-2012-0471.html" source="CVE"/>
        <reference ref_id="CVE-2012-0472" ref_url="http://linux.oracle.com/cve/CVE-2012-0472.html" source="CVE"/>
        <reference ref_id="CVE-2012-0473" ref_url="http://linux.oracle.com/cve/CVE-2012-0473.html" source="CVE"/>
        <reference ref_id="CVE-2012-0474" ref_url="http://linux.oracle.com/cve/CVE-2012-0474.html" source="CVE"/>
        <reference ref_id="CVE-2012-0477" ref_url="http://linux.oracle.com/cve/CVE-2012-0477.html" source="CVE"/>
        <reference ref_id="CVE-2012-0478" ref_url="http://linux.oracle.com/cve/CVE-2012-0478.html" source="CVE"/>
        <reference ref_id="CVE-2012-0479" ref_url="http://linux.oracle.com/cve/CVE-2012-0479.html" source="CVE"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:27.970-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:45.676-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:43.173-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23660 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:28.759-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:07.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:110068"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:109913"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23659" version="173" class="patch">
      <metadata>
        <title>ELSA-2011:1434: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2011:1434-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1434.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2094" ref_url="http://linux.oracle.com/cve/CVE-2011-2094.html" source="CVE"/>
        <reference ref_id="CVE-2011-2095" ref_url="http://linux.oracle.com/cve/CVE-2011-2095.html" source="CVE"/>
        <reference ref_id="CVE-2011-2096" ref_url="http://linux.oracle.com/cve/CVE-2011-2096.html" source="CVE"/>
        <reference ref_id="CVE-2011-2097" ref_url="http://linux.oracle.com/cve/CVE-2011-2097.html" source="CVE"/>
        <reference ref_id="CVE-2011-2098" ref_url="http://linux.oracle.com/cve/CVE-2011-2098.html" source="CVE"/>
        <reference ref_id="CVE-2011-2099" ref_url="http://linux.oracle.com/cve/CVE-2011-2099.html" source="CVE"/>
        <reference ref_id="CVE-2011-2101" ref_url="http://linux.oracle.com/cve/CVE-2011-2101.html" source="CVE"/>
        <reference ref_id="CVE-2011-2104" ref_url="http://linux.oracle.com/cve/CVE-2011-2104.html" source="CVE"/>
        <reference ref_id="CVE-2011-2105" ref_url="http://linux.oracle.com/cve/CVE-2011-2105.html" source="CVE"/>
        <reference ref_id="CVE-2011-2107" ref_url="http://linux.oracle.com/cve/CVE-2011-2107.html" source="CVE"/>
        <reference ref_id="CVE-2011-2130" ref_url="http://linux.oracle.com/cve/CVE-2011-2130.html" source="CVE"/>
        <reference ref_id="CVE-2011-2134" ref_url="http://linux.oracle.com/cve/CVE-2011-2134.html" source="CVE"/>
        <reference ref_id="CVE-2011-2135" ref_url="http://linux.oracle.com/cve/CVE-2011-2135.html" source="CVE"/>
        <reference ref_id="CVE-2011-2136" ref_url="http://linux.oracle.com/cve/CVE-2011-2136.html" source="CVE"/>
        <reference ref_id="CVE-2011-2137" ref_url="http://linux.oracle.com/cve/CVE-2011-2137.html" source="CVE"/>
        <reference ref_id="CVE-2011-2138" ref_url="http://linux.oracle.com/cve/CVE-2011-2138.html" source="CVE"/>
        <reference ref_id="CVE-2011-2139" ref_url="http://linux.oracle.com/cve/CVE-2011-2139.html" source="CVE"/>
        <reference ref_id="CVE-2011-2140" ref_url="http://linux.oracle.com/cve/CVE-2011-2140.html" source="CVE"/>
        <reference ref_id="CVE-2011-2414" ref_url="http://linux.oracle.com/cve/CVE-2011-2414.html" source="CVE"/>
        <reference ref_id="CVE-2011-2415" ref_url="http://linux.oracle.com/cve/CVE-2011-2415.html" source="CVE"/>
        <reference ref_id="CVE-2011-2416" ref_url="http://linux.oracle.com/cve/CVE-2011-2416.html" source="CVE"/>
        <reference ref_id="CVE-2011-2417" ref_url="http://linux.oracle.com/cve/CVE-2011-2417.html" source="CVE"/>
        <reference ref_id="CVE-2011-2424" ref_url="http://linux.oracle.com/cve/CVE-2011-2424.html" source="CVE"/>
        <reference ref_id="CVE-2011-2425" ref_url="http://linux.oracle.com/cve/CVE-2011-2425.html" source="CVE"/>
        <reference ref_id="CVE-2011-2426" ref_url="http://linux.oracle.com/cve/CVE-2011-2426.html" source="CVE"/>
        <reference ref_id="CVE-2011-2427" ref_url="http://linux.oracle.com/cve/CVE-2011-2427.html" source="CVE"/>
        <reference ref_id="CVE-2011-2428" ref_url="http://linux.oracle.com/cve/CVE-2011-2428.html" source="CVE"/>
        <reference ref_id="CVE-2011-2429" ref_url="http://linux.oracle.com/cve/CVE-2011-2429.html" source="CVE"/>
        <reference ref_id="CVE-2011-2430" ref_url="http://linux.oracle.com/cve/CVE-2011-2430.html" source="CVE"/>
        <reference ref_id="CVE-2011-2431" ref_url="http://linux.oracle.com/cve/CVE-2011-2431.html" source="CVE"/>
        <reference ref_id="CVE-2011-2432" ref_url="http://linux.oracle.com/cve/CVE-2011-2432.html" source="CVE"/>
        <reference ref_id="CVE-2011-2433" ref_url="http://linux.oracle.com/cve/CVE-2011-2433.html" source="CVE"/>
        <reference ref_id="CVE-2011-2434" ref_url="http://linux.oracle.com/cve/CVE-2011-2434.html" source="CVE"/>
        <reference ref_id="CVE-2011-2435" ref_url="http://linux.oracle.com/cve/CVE-2011-2435.html" source="CVE"/>
        <reference ref_id="CVE-2011-2436" ref_url="http://linux.oracle.com/cve/CVE-2011-2436.html" source="CVE"/>
        <reference ref_id="CVE-2011-2437" ref_url="http://linux.oracle.com/cve/CVE-2011-2437.html" source="CVE"/>
        <reference ref_id="CVE-2011-2438" ref_url="http://linux.oracle.com/cve/CVE-2011-2438.html" source="CVE"/>
        <reference ref_id="CVE-2011-2439" ref_url="http://linux.oracle.com/cve/CVE-2011-2439.html" source="CVE"/>
        <reference ref_id="CVE-2011-2440" ref_url="http://linux.oracle.com/cve/CVE-2011-2440.html" source="CVE"/>
        <reference ref_id="CVE-2011-2442" ref_url="http://linux.oracle.com/cve/CVE-2011-2442.html" source="CVE"/>
        <reference ref_id="CVE-2011-2444" ref_url="http://linux.oracle.com/cve/CVE-2011-2444.html" source="CVE"/>
        <reference ref_id="CVE-2011-4374" ref_url="http://linux.oracle.com/cve/CVE-2011-4374.html" source="CVE"/>
        <description>Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:56.435-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.838-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:41.350-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23659 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:28.433-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:06.260-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:109073"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:109518"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:109196"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:109129"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23658" version="25" class="patch">
      <metadata>
        <title>ELSA-2011:1221: samba and cifs-utils security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cifs-utils</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2011:1221-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1221.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1678" ref_url="http://linux.oracle.com/cve/CVE-2011-1678.html" source="CVE"/>
        <reference ref_id="CVE-2011-2522" ref_url="http://linux.oracle.com/cve/CVE-2011-2522.html" source="CVE"/>
        <reference ref_id="CVE-2011-2694" ref_url="http://linux.oracle.com/cve/CVE-2011-2694.html" source="CVE"/>
        <reference ref_id="CVE-2011-2724" ref_url="http://linux.oracle.com/cve/CVE-2011-2724.html" source="CVE"/>
        <reference ref_id="CVE-2011-3585" ref_url="http://linux.oracle.com/cve/CVE-2011-3585.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:15.171-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.679-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:41.042-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23658 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.247-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:06.062-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="cifs-utils is earlier than 0:4.8.1-2.el6_1.2" test_ref="oval:org.mitre.oval:tst:109265"/>
          <criterion comment="samba-client is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109221"/>
          <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109119"/>
          <criterion comment="samba is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109140"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109325"/>
          <criterion comment="samba-common is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:108882"/>
          <criterion comment="samba-winbind is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109182"/>
          <criterion comment="samba-doc is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109069"/>
          <criterion comment="samba-winbind-devel is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109075"/>
          <criterion comment="samba-winbind-clients is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109174"/>
          <criterion comment="libsmbclient is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:108335"/>
          <criterion comment="samba-swat is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109215"/>
          <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:109079"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23657" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1366: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1366-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1366.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3412" ref_url="http://linux.oracle.com/cve/CVE-2012-3412.html" source="CVE"/>
        <description>The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:10.474-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.587-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:40.893-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23657 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:28.634-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:05.921-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:110951"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:111040"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:111212"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:111210"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:111194"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:110703"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:110988"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:111221"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:111200"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:111121"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:110828"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:110868"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23656" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0934: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2010:0934-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0934.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3654" ref_url="http://linux.oracle.com/cve/CVE-2010-3654.html" source="CVE"/>
        <reference ref_id="CVE-2010-4091" ref_url="http://linux.oracle.com/cve/CVE-2010-4091.html" source="CVE"/>
        <description>The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:30.064-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.496-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:40.741-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23656 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.603-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:05.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.1-1.el5" test_ref="oval:org.mitre.oval:tst:108034"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.1-1.el5" test_ref="oval:org.mitre.oval:tst:107655"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.1-1.el6" test_ref="oval:org.mitre.oval:tst:107969"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.1-1.el6" test_ref="oval:org.mitre.oval:tst:107774"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23655" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1085: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2011:1085-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1085.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0226" ref_url="http://linux.oracle.com/cve/CVE-2011-0226.html" source="CVE"/>
        <description>Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:10.897-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.430-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:40.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23655 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:26.603-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:05.669-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.6" test_ref="oval:org.mitre.oval:tst:109156"/>
          <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.6" test_ref="oval:org.mitre.oval:tst:109029"/>
          <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.6" test_ref="oval:org.mitre.oval:tst:109122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23654" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0888: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2010:0888-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0888.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3864" ref_url="http://linux.oracle.com/cve/CVE-2010-3864.html" source="CVE"/>
        <description>Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to execute arbitrary code via client data that triggers a heap-based buffer overflow, related to (1) the TLS server name extension and (2) elliptic curve cryptography.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:37.676-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.360-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:40.486-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23654 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.803-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:05.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl-devel is earlier than 0:1.0.0-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:108220"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:107901"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:108213"/>
          <criterion comment="openssl is earlier than 0:1.0.0-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:108030"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23653" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0517: util-linux-ng security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>util-linux-ng</product>
        </affected>
        <reference ref_id="ELSA-2013:0517-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0517.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0157" ref_url="http://linux.oracle.com/cve/CVE-2013-0157.html" source="CVE"/>
        <description>(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:45.984-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.280-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:40.376-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23653 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:24.582-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:05.479-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="util-linux-ng is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:111528"/>
          <criterion comment="uuidd is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:111554"/>
          <criterion comment="libuuid is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:111322"/>
          <criterion comment="libuuid-devel is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:111431"/>
          <criterion comment="libblkid is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:111548"/>
          <criterion comment="libblkid-devel is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:111454"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23652" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:0374: thunderbird security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:0374-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0374.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
This erratum blacklists a small number of HTTPS certificates. (BZ#689430)
This update also fixes the following bug:
* The RHSA-2011:0312 and RHSA-2011:0311 updates introduced a regression,
preventing some Java content and plug-ins written in Java from loading.
With this update, the Java content and plug-ins work as expected.
(BZ#683076)
All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:21.077-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.220-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:40.306-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23652 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.351-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:05.387-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-15.el5_6" test_ref="oval:org.mitre.oval:tst:108510"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:3.1.9-3.el6_0" test_ref="oval:org.mitre.oval:tst:108013"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23651" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0329: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0329-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0329.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0714" ref_url="http://linux.oracle.com/cve/CVE-2011-0714.html" source="CVE"/>
        <description>Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:26.737-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:44.131-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:40.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23651 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:23.495-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:05.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:107999"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:108660"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:107978"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:108369"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:107823"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:108481"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:108516"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:108180"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:108614"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:108709"/>
          <criterion comment="kernel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:108619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23650" version="105" class="patch">
      <metadata>
        <title>ELSA-2013:0758: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2013:0758-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0758.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-1491" ref_url="http://linux.oracle.com/cve/CVE-2013-1491.html" source="CVE"/>
        <reference ref_id="CVE-2013-1518" ref_url="http://linux.oracle.com/cve/CVE-2013-1518.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1540" ref_url="http://linux.oracle.com/cve/CVE-2013-1540.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1558" ref_url="http://linux.oracle.com/cve/CVE-2013-1558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1563" ref_url="http://linux.oracle.com/cve/CVE-2013-1563.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2394" ref_url="http://linux.oracle.com/cve/CVE-2013-2394.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2418" ref_url="http://linux.oracle.com/cve/CVE-2013-2418.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2422" ref_url="http://linux.oracle.com/cve/CVE-2013-2422.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2432" ref_url="http://linux.oracle.com/cve/CVE-2013-2432.html" source="CVE"/>
        <reference ref_id="CVE-2013-2433" ref_url="http://linux.oracle.com/cve/CVE-2013-2433.html" source="CVE"/>
        <reference ref_id="CVE-2013-2435" ref_url="http://linux.oracle.com/cve/CVE-2013-2435.html" source="CVE"/>
        <reference ref_id="CVE-2013-2439" ref_url="http://linux.oracle.com/cve/CVE-2013-2439.html" source="CVE"/>
        <reference ref_id="CVE-2013-2440" ref_url="http://linux.oracle.com/cve/CVE-2013-2440.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:35.962-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:43.637-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:39.140-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23650 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:21.330-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:04.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:112021"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111990"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111345"/>
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111994"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111786"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:111395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23648" version="97" class="patch">
      <metadata>
        <title>ELSA-2013:0823: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:0823-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0823.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0170" ref_url="http://linux.oracle.com/cve/CVE-2013-0170.html" source="CVE"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-1491" ref_url="http://linux.oracle.com/cve/CVE-2013-1491.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1540" ref_url="http://linux.oracle.com/cve/CVE-2013-1540.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1563" ref_url="http://linux.oracle.com/cve/CVE-2013-1563.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2394" ref_url="http://linux.oracle.com/cve/CVE-2013-2394.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2418" ref_url="http://linux.oracle.com/cve/CVE-2013-2418.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2422" ref_url="http://linux.oracle.com/cve/CVE-2013-2422.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2432" ref_url="http://linux.oracle.com/cve/CVE-2013-2432.html" source="CVE"/>
        <reference ref_id="CVE-2013-2433" ref_url="http://linux.oracle.com/cve/CVE-2013-2433.html" source="CVE"/>
        <reference ref_id="CVE-2013-2435" ref_url="http://linux.oracle.com/cve/CVE-2013-2435.html" source="CVE"/>
        <reference ref_id="CVE-2013-2440" ref_url="http://linux.oracle.com/cve/CVE-2013-2440.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:55.643-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:43.069-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:38.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23648 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:28.139-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:03.840-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111998"/>
          <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112030"/>
          <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112051"/>
          <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112033"/>
          <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111872"/>
          <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111923"/>
          <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23647" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0465: samba security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2012:0465-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-0465.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1182" ref_url="http://linux.oracle.com/cve/CVE-2012-1182.html" source="CVE"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:02.643-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.968-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:38.002-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23647 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:24.703-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:03.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-client is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:110120"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:109635"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:110161"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:109969"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:110016"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:109983"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-client is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109978"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109982"/>
            <criterion comment="samba is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109586"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109869"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109832"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109858"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109576"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:110079"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:110082"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109358"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109571"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:109799"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23645" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0180: pango security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>evolution28-pango</product>
          <product>pango</product>
        </affected>
        <reference ref_id="ELSA-2011:0180-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0180.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0020" ref_url="http://linux.oracle.com/cve/CVE-2011-0020.html" source="CVE"/>
        <description>Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:34.807-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.841-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:37.805-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23645 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:23.848-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:03.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pango is earlier than 0:1.28.1-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:108181"/>
          <criterion comment="pango-devel is earlier than 0:1.28.1-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:108242"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23644" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1102: libsoup security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libsoup</product>
        </affected>
        <reference ref_id="ELSA-2011:1102-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1102.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2524" ref_url="http://linux.oracle.com/cve/CVE-2011-2524.html" source="CVE"/>
        <description>Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:09.043-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.775-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:37.709-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23644 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:25.044-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:03.390-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libsoup-devel is earlier than 0:2.28.2-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:109253"/>
          <criterion comment="libsoup is earlier than 0:2.28.2-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:109293"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23643" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1363: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:1363-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1363.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5166" ref_url="http://linux.oracle.com/cve/CVE-2012-5166.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:07.633-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.660-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:37.571-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23643 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:21.498-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:03.271-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110916"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110599"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:111098"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110484"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110470"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:111135"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:110955"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:111042"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110962"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:111216"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110869"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110726"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110702"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:110859"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23642" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1461: libproxy security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libproxy</product>
        </affected>
        <reference ref_id="ELSA-2012:1461-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1461.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4505" ref_url="http://linux.oracle.com/cve/CVE-2012-4505.html" source="CVE"/>
        <description>Heap-based buffer overflow in the px_pac_reload function in lib/pac.c in libproxy 0.2.x and 0.3.x allows remote servers to have an unspecified impact via a crafted Content-Length size in an HTTP response header for a proxy.pac file request, a different vulnerability than CVE-2012-4504.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:13.144-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.579-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:37.451-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23642 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:27.164-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:03.163-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libproxy-bin is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:110991"/>
          <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:111251"/>
          <criterion comment="libproxy-devel is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:110687"/>
          <criterion comment="libproxy-webkit is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:110733"/>
          <criterion comment="libproxy is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:111209"/>
          <criterion comment="libproxy-gnome is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:111125"/>
          <criterion comment="libproxy-python is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:111076"/>
          <criterion comment="libproxy-kde is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:111282"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23641" version="58" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0097: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2014:0097-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0097.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5878" ref_url="http://linux.oracle.com/cve/CVE-2013-5878.html" source="CVE"/>
        <reference ref_id="CVE-2013-5884" ref_url="http://linux.oracle.com/cve/CVE-2013-5884.html" source="CVE"/>
        <reference ref_id="CVE-2013-5896" ref_url="http://linux.oracle.com/cve/CVE-2013-5896.html" source="CVE"/>
        <reference ref_id="CVE-2013-5907" ref_url="http://linux.oracle.com/cve/CVE-2013-5907.html" source="CVE"/>
        <reference ref_id="CVE-2013-5910" ref_url="http://linux.oracle.com/cve/CVE-2013-5910.html" source="CVE"/>
        <reference ref_id="CVE-2014-0368" ref_url="http://linux.oracle.com/cve/CVE-2014-0368.html" source="CVE"/>
        <reference ref_id="CVE-2014-0373" ref_url="http://linux.oracle.com/cve/CVE-2014-0373.html" source="CVE"/>
        <reference ref_id="CVE-2014-0376" ref_url="http://linux.oracle.com/cve/CVE-2014-0376.html" source="CVE"/>
        <reference ref_id="CVE-2014-0411" ref_url="http://linux.oracle.com/cve/CVE-2014-0411.html" source="CVE"/>
        <reference ref_id="CVE-2014-0416" ref_url="http://linux.oracle.com/cve/CVE-2014-0416.html" source="CVE"/>
        <reference ref_id="CVE-2014-0422" ref_url="http://linux.oracle.com/cve/CVE-2014-0422.html" source="CVE"/>
        <reference ref_id="CVE-2014-0423" ref_url="http://linux.oracle.com/cve/CVE-2014-0423.html" source="CVE"/>
        <reference ref_id="CVE-2014-0428" ref_url="http://linux.oracle.com/cve/CVE-2014-0428.html" source="CVE"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.	NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:08.067-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.291-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:36.903-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23641 - optimisation of Oracle Linux content" date="2014-05-05T17:30:00.036-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:32:23.266-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:02.796-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:54:43.542-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:54:43.542-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:107985"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:107833"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:107975"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:107286"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:108054"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:107190"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:107809"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:107867"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:108016"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:107270"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23640" version="21" class="patch">
      <metadata>
        <title>ELSA-2011:0311: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:0311-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0311.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1585" ref_url="http://linux.oracle.com/cve/CVE-2010-1585.html" source="CVE"/>
        <reference ref_id="CVE-2011-0053" ref_url="http://linux.oracle.com/cve/CVE-2011-0053.html" source="CVE"/>
        <reference ref_id="CVE-2011-0061" ref_url="http://linux.oracle.com/cve/CVE-2011-0061.html" source="CVE"/>
        <reference ref_id="CVE-2011-0062" ref_url="http://linux.oracle.com/cve/CVE-2011-0062.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:41.946-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.168-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:36.699-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23640 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:33.277-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:00.727-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.8-4.el6_0" test_ref="oval:org.mitre.oval:tst:108185"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23639" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1187: dovecot security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference ref_id="ELSA-2011:1187-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1187.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1929" ref_url="http://linux.oracle.com/cve/CVE-2011-1929.html" source="CVE"/>
        <description>lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:21.309-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:42.081-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:36.583-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23639 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:10.925-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:02.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="dovecot is earlier than 0:1.0.7-7.el5_7.1" test_ref="oval:org.mitre.oval:tst:108428"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109169"/>
            <criterion comment="dovecot-mysql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109177"/>
            <criterion comment="dovecot is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:108652"/>
            <criterion comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109308"/>
            <criterion comment="dovecot-devel is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:109254"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23638" version="53" class="patch">
      <metadata>
        <title>ELSA-2012:0139: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2012:0139-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0139.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3563" ref_url="http://linux.oracle.com/cve/CVE-2011-3563.html" source="CVE"/>
        <reference ref_id="CVE-2011-3571" ref_url="http://linux.oracle.com/cve/CVE-2011-3571.html" source="CVE"/>
        <reference ref_id="CVE-2011-5035" ref_url="http://linux.oracle.com/cve/CVE-2011-5035.html" source="CVE"/>
        <reference ref_id="CVE-2012-0498" ref_url="http://linux.oracle.com/cve/CVE-2012-0498.html" source="CVE"/>
        <reference ref_id="CVE-2012-0499" ref_url="http://linux.oracle.com/cve/CVE-2012-0499.html" source="CVE"/>
        <reference ref_id="CVE-2012-0500" ref_url="http://linux.oracle.com/cve/CVE-2012-0500.html" source="CVE"/>
        <reference ref_id="CVE-2012-0501" ref_url="http://linux.oracle.com/cve/CVE-2012-0501.html" source="CVE"/>
        <reference ref_id="CVE-2012-0502" ref_url="http://linux.oracle.com/cve/CVE-2012-0502.html" source="CVE"/>
        <reference ref_id="CVE-2012-0503" ref_url="http://linux.oracle.com/cve/CVE-2012-0503.html" source="CVE"/>
        <reference ref_id="CVE-2012-0505" ref_url="http://linux.oracle.com/cve/CVE-2012-0505.html" source="CVE"/>
        <reference ref_id="CVE-2012-0506" ref_url="http://linux.oracle.com/cve/CVE-2012-0506.html" source="CVE"/>
        <reference ref_id="CVE-2012-0507" ref_url="http://linux.oracle.com/cve/CVE-2012-0507.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.	NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:15.340-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:41.753-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:36.067-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23638 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:09.689-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:02.304-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:109980"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:109783"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:109515"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:109941"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:109986"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:109591"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23637" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0455: polkit security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>polkit</product>
        </affected>
        <reference ref_id="ELSA-2011:0455-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0455.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1485" ref_url="http://linux.oracle.com/cve/CVE-2011-1485.html" source="CVE"/>
        <description>Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:44.401-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:41.678-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:35.959-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23637 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:13.693-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:02.200-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="polkit is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108260"/>
          <criterion comment="polkit-desktop-policy is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108753"/>
          <criterion comment="polkit-docs is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108711"/>
          <criterion comment="polkit-devel is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108381"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23636" version="61" class="patch">
      <metadata>
        <title>ELSA-2011:1189: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:1189-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1189.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1182" ref_url="http://linux.oracle.com/cve/CVE-2011-1182.html" source="CVE"/>
        <reference ref_id="CVE-2011-1576" ref_url="http://linux.oracle.com/cve/CVE-2011-1576.html" source="CVE"/>
        <reference ref_id="CVE-2011-1593" ref_url="http://linux.oracle.com/cve/CVE-2011-1593.html" source="CVE"/>
        <reference ref_id="CVE-2011-1776" ref_url="http://linux.oracle.com/cve/CVE-2011-1776.html" source="CVE"/>
        <reference ref_id="CVE-2011-1898" ref_url="http://linux.oracle.com/cve/CVE-2011-1898.html" source="CVE"/>
        <reference ref_id="CVE-2011-2183" ref_url="http://linux.oracle.com/cve/CVE-2011-2183.html" source="CVE"/>
        <reference ref_id="CVE-2011-2213" ref_url="http://linux.oracle.com/cve/CVE-2011-2213.html" source="CVE"/>
        <reference ref_id="CVE-2011-2491" ref_url="http://linux.oracle.com/cve/CVE-2011-2491.html" source="CVE"/>
        <reference ref_id="CVE-2011-2492" ref_url="http://linux.oracle.com/cve/CVE-2011-2492.html" source="CVE"/>
        <reference ref_id="CVE-2011-2495" ref_url="http://linux.oracle.com/cve/CVE-2011-2495.html" source="CVE"/>
        <reference ref_id="CVE-2011-2497" ref_url="http://linux.oracle.com/cve/CVE-2011-2497.html" source="CVE"/>
        <reference ref_id="CVE-2011-2517" ref_url="http://linux.oracle.com/cve/CVE-2011-2517.html" source="CVE"/>
        <reference ref_id="CVE-2011-2689" ref_url="http://linux.oracle.com/cve/CVE-2011-2689.html" source="CVE"/>
        <reference ref_id="CVE-2011-2695" ref_url="http://linux.oracle.com/cve/CVE-2011-2695.html" source="CVE"/>
        <description>Multiple off-by-one errors in the ext4 subsystem in the Linux kernel before 3.0-rc5 allow local users to cause a denial of service (BUG_ON and system crash) by accessing a sparse file in extent format with a write operation involving a block number corresponding to the largest possible 32-bit unsigned integer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:13.816-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:41.343-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:35.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23636 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:15.539-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:01.768-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:109137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:109301"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:109191"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:108754"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:109061"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:109298"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:109280"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:108944"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:108980"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:108853"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:109053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23633" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0332: scsi-target-utils security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference ref_id="ELSA-2011:0332-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0332.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0001" ref_url="http://linux.oracle.com/cve/CVE-2011-0001.html" source="CVE"/>
        <description>Double free vulnerability in the iscsi_rx_handler function (usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown vectors related to a buffer overflow during iscsi login.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:20.471-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:41.191-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:35.089-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23633 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:05.971-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:01.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="scsi-target-utils is earlier than 0:1.0.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107980"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23632" version="37" class="patch">
      <metadata>
        <title>ELSA-2014:0164: mysql security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference ref_id="ELSA-2014:0164-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0164.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5908" ref_url="http://linux.oracle.com/cve/CVE-2013-5908.html" source="CVE"/>
        <reference ref_id="CVE-2014-0001" ref_url="http://linux.oracle.com/cve/CVE-2014-0001.html" source="CVE"/>
        <reference ref_id="CVE-2014-0386" ref_url="http://linux.oracle.com/cve/CVE-2014-0386.html" source="CVE"/>
        <reference ref_id="CVE-2014-0393" ref_url="http://linux.oracle.com/cve/CVE-2014-0393.html" source="CVE"/>
        <reference ref_id="CVE-2014-0401" ref_url="http://linux.oracle.com/cve/CVE-2014-0401.html" source="CVE"/>
        <reference ref_id="CVE-2014-0402" ref_url="http://linux.oracle.com/cve/CVE-2014-0402.html" source="CVE"/>
        <reference ref_id="CVE-2014-0412" ref_url="http://linux.oracle.com/cve/CVE-2014-0412.html" source="CVE"/>
        <reference ref_id="CVE-2014-0437" ref_url="http://linux.oracle.com/cve/CVE-2014-0437.html" source="CVE"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:53:36.952-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.985-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:34.701-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23632 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:06.550-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:01.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="mysql-devel is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:112536"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:112603"/>
          <criterion comment="mysql-test is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:112618"/>
          <criterion comment="mysql-server is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:112403"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:112871"/>
          <criterion comment="mysql is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:112884"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:112605"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:112322"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23631" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0899: openldap security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference ref_id="ELSA-2012:0899-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0899.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1164" ref_url="http://linux.oracle.com/cve/CVE-2012-1164.html" source="CVE"/>
        <description>slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:17.027-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.874-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:34.590-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23631 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:15.423-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:01.167-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openldap-servers is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:110584"/>
          <criterion comment="openldap is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:110399"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:110636"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:110540"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:110620"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23630" version="49" class="patch">
      <metadata>
        <title>ELSA-2011:1445: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1445-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1445.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2445" ref_url="http://linux.oracle.com/cve/CVE-2011-2445.html" source="CVE"/>
        <reference ref_id="CVE-2011-2450" ref_url="http://linux.oracle.com/cve/CVE-2011-2450.html" source="CVE"/>
        <reference ref_id="CVE-2011-2451" ref_url="http://linux.oracle.com/cve/CVE-2011-2451.html" source="CVE"/>
        <reference ref_id="CVE-2011-2452" ref_url="http://linux.oracle.com/cve/CVE-2011-2452.html" source="CVE"/>
        <reference ref_id="CVE-2011-2453" ref_url="http://linux.oracle.com/cve/CVE-2011-2453.html" source="CVE"/>
        <reference ref_id="CVE-2011-2454" ref_url="http://linux.oracle.com/cve/CVE-2011-2454.html" source="CVE"/>
        <reference ref_id="CVE-2011-2455" ref_url="http://linux.oracle.com/cve/CVE-2011-2455.html" source="CVE"/>
        <reference ref_id="CVE-2011-2456" ref_url="http://linux.oracle.com/cve/CVE-2011-2456.html" source="CVE"/>
        <reference ref_id="CVE-2011-2457" ref_url="http://linux.oracle.com/cve/CVE-2011-2457.html" source="CVE"/>
        <reference ref_id="CVE-2011-2459" ref_url="http://linux.oracle.com/cve/CVE-2011-2459.html" source="CVE"/>
        <reference ref_id="CVE-2011-2460" ref_url="http://linux.oracle.com/cve/CVE-2011-2460.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, and CVE-2011-2459.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:05.840-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.464-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:34.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23630 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:15.126-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.833-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el5" test_ref="oval:org.mitre.oval:tst:108718"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el6" test_ref="oval:org.mitre.oval:tst:109647"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23629" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1821: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2011:1821-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1821.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4601" ref_url="http://linux.oracle.com/cve/CVE-2011-4601.html" source="CVE"/>
        <reference ref_id="CVE-2011-4602" ref_url="http://linux.oracle.com/cve/CVE-2011-4602.html" source="CVE"/>
        <description>The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:58.821-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.361-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:33.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23629 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:08.297-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.704-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pidgin-perl is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:109697"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:109361"/>
          <criterion comment="pidgin-docs is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:109359"/>
          <criterion comment="libpurple is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:109613"/>
          <criterion comment="libpurple-perl is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:109715"/>
          <criterion comment="finch-devel is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:109658"/>
          <criterion comment="finch is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:109237"/>
          <criterion comment="libpurple-devel is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:109617"/>
          <criterion comment="pidgin-devel is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:109726"/>
          <criterion comment="pidgin is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:108772"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23628" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1418: libtar security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtar</product>
        </affected>
        <reference ref_id="ELSA-2013:1418-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1418.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4390" ref_url="http://linux.oracle.com/cve/CVE-2013-4390.html" source="CVE"/>
        <description>Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the resource parameter, related to "a custom login form and XSS."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:07.058-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.296-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:33.866-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23628 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.641-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libtar-devel is earlier than 0:1.2.11-17.el6_4.1" test_ref="oval:org.mitre.oval:tst:112010"/>
          <criterion comment="libtar is earlier than 0:1.2.11-17.el6_4.1" test_ref="oval:org.mitre.oval:tst:112395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23627" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0328: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference ref_id="ELSA-2011:0328-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0328.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0715" ref_url="http://linux.oracle.com/cve/CVE-2011-0715.html" source="CVE"/>
        <description>The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:24.179-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.217-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:33.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23627 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:16.020-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:108497"/>
          <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:108384"/>
          <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:108551"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:108686"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:108360"/>
          <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:108429"/>
          <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:108657"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:108543"/>
          <criterion comment="subversion is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:108630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23626" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1385: kdelibs and kdelibs3 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>kdelibs</product>
          <product>kdelibs3</product>
        </affected>
        <reference ref_id="ELSA-2011:1385-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1385.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3365" ref_url="http://linux.oracle.com/cve/CVE-2011-3365.html" source="CVE"/>
        <description>The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:54.967-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.137-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:33.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23626 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.998-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.363-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:109481"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:108507"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:109056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="kdelibs3-apidocs is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:109343"/>
            <criterion comment="kdelibs3-devel is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:109278"/>
            <criterion comment="kdelibs3 is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:109454"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23625" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0335: tomcat6 security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference ref_id="ELSA-2011:0335-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0335.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4476" ref_url="http://linux.oracle.com/cve/CVE-2010-4476.html" source="CVE"/>
        <reference ref_id="CVE-2011-0534" ref_url="http://linux.oracle.com/cve/CVE-2011-0534.html" source="CVE"/>
        <description>Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:18.155-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:40.041-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:33.445-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23625 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:15.330-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.245-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108029"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108644"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108733"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108259"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108309"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108633"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108681"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108466"/>
          <criterion comment="tomcat6-log4j is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108401"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:108506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23624" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0930: NetworkManager security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>NetworkManager</product>
        </affected>
        <reference ref_id="ELSA-2011:0930-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0930.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2176" ref_url="http://linux.oracle.com/cve/CVE-2011-2176.html" source="CVE"/>
        <description>GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:11.513-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:39.958-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:33.326-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23624 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:08.617-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="NetworkManager is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:108850"/>
          <criterion comment="NetworkManager-devel is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:108579"/>
          <criterion comment="NetworkManager-gnome is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:108828"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:109114"/>
          <criterion comment="NetworkManager-glib is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:109102"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23623" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1289: librsvg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>librsvg2</product>
        </affected>
        <reference ref_id="ELSA-2011:1289-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1289.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3146" ref_url="http://linux.oracle.com/cve/CVE-2011-3146.html" source="CVE"/>
        <description>librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary code via a SVG file with a node with the element name starting with "fe," which is misidentified as a RsvgFilterPrimitive.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:09.072-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:39.882-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:33.225-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23623 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.146-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:05:00.044-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="librsvg2-devel is earlier than 0:2.26.0-5.el6_1.1" test_ref="oval:org.mitre.oval:tst:109384"/>
          <criterion comment="librsvg2 is earlier than 0:2.26.0-5.el6_1.1" test_ref="oval:org.mitre.oval:tst:109382"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23622" version="69" class="patch">
      <metadata>
        <title>ELSA-2013:0855: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:0855-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0855.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-1491" ref_url="http://linux.oracle.com/cve/CVE-2013-1491.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2394" ref_url="http://linux.oracle.com/cve/CVE-2013-2394.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2432" ref_url="http://linux.oracle.com/cve/CVE-2013-2432.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2394 and CVE-2013-1491.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:54.224-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:39.411-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:32.499-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23622 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:13.820-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:59.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111980"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112105"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111800"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:112104"/>
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111220"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111651"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:111550"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23621" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0018: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference ref_id="ELSA-2014:0018-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0018.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6462" ref_url="http://linux.oracle.com/cve/CVE-2013-6462.html" source="CVE"/>
        <description>Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:07.233-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:39.336-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:32.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23621 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:10.620-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:59.495-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:53:45.260-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:53:45.260-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:107053"/>
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:107841"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:108010"/>
            <criterion comment="libXfont is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:107811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23620" version="49" class="patch">
      <metadata>
        <title>ELSA-2011:1350: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:1350-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1350.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1160" ref_url="http://linux.oracle.com/cve/CVE-2011-1160.html" source="CVE"/>
        <reference ref_id="CVE-2011-1745" ref_url="http://linux.oracle.com/cve/CVE-2011-1745.html" source="CVE"/>
        <reference ref_id="CVE-2011-1746" ref_url="http://linux.oracle.com/cve/CVE-2011-1746.html" source="CVE"/>
        <reference ref_id="CVE-2011-1833" ref_url="http://linux.oracle.com/cve/CVE-2011-1833.html" source="CVE"/>
        <reference ref_id="CVE-2011-2022" ref_url="http://linux.oracle.com/cve/CVE-2011-2022.html" source="CVE"/>
        <reference ref_id="CVE-2011-2484" ref_url="http://linux.oracle.com/cve/CVE-2011-2484.html" source="CVE"/>
        <reference ref_id="CVE-2011-2496" ref_url="http://linux.oracle.com/cve/CVE-2011-2496.html" source="CVE"/>
        <reference ref_id="CVE-2011-2521" ref_url="http://linux.oracle.com/cve/CVE-2011-2521.html" source="CVE"/>
        <reference ref_id="CVE-2011-2723" ref_url="http://linux.oracle.com/cve/CVE-2011-2723.html" source="CVE"/>
        <reference ref_id="CVE-2011-2898" ref_url="http://linux.oracle.com/cve/CVE-2011-2898.html" source="CVE"/>
        <reference ref_id="CVE-2011-2918" ref_url="http://linux.oracle.com/cve/CVE-2011-2918.html" source="CVE"/>
        <description>The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:13.066-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:39.065-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:31.855-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23620 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.256-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:59.144-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109305"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109285"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109012"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109367"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109292"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109336"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:108490"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109235"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109349"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109083"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:109375"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23619" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0868: haproxy security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>haproxy</product>
        </affected>
        <reference ref_id="ELSA-2013:0868-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0868.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1912" ref_url="http://linux.oracle.com/cve/CVE-2013-1912.html" source="CVE"/>
        <description>Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:54.708-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:39.000-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:31.751-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23619 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:10.370-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:59.052-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="haproxy is earlier than 0:1.4.22-4.el6_4" test_ref="oval:org.mitre.oval:tst:112048"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23618" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0950: apr-util security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>apr-util</product>
        </affected>
        <reference ref_id="ELSA-2010:0950-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0950.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1623" ref_url="http://linux.oracle.com/cve/CVE-2010-1623.html" source="CVE"/>
        <description>Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:37.990-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.915-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:31.618-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23618 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:11.273-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.931-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-util-mysql is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:108022"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:107888"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:108241"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:108151"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-util-mysql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108239"/>
            <criterion comment="apr-util-odbc is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108117"/>
            <criterion comment="apr-util-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108225"/>
            <criterion comment="apr-util-ldap is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108186"/>
            <criterion comment="apr-util is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107924"/>
            <criterion comment="apr-util-pgsql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108057"/>
            <criterion comment="apr-util-sqlite is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107998"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23617" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1455: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2011:1455-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1455.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3439" ref_url="http://linux.oracle.com/cve/CVE-2011-3439.html" source="CVE"/>
        <description>FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:54.336-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.839-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:31.479-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23617 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.043-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.824-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:109525"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:109630"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:109500"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:109089"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:109145"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:109618"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23616" version="25" class="patch">
      <metadata>
        <title>ELSA-2011:0836: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0836-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0836.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3858" ref_url="http://linux.oracle.com/cve/CVE-2010-3858.html" source="CVE"/>
        <reference ref_id="CVE-2011-1598" ref_url="http://linux.oracle.com/cve/CVE-2011-1598.html" source="CVE"/>
        <reference ref_id="CVE-2011-1748" ref_url="http://linux.oracle.com/cve/CVE-2011-1748.html" source="CVE"/>
        <reference ref_id="CVE-2011-1770" ref_url="http://linux.oracle.com/cve/CVE-2011-1770.html" source="CVE"/>
        <reference ref_id="CVE-2011-1771" ref_url="http://linux.oracle.com/cve/CVE-2011-1771.html" source="CVE"/>
        <description>The cifs_close function in fs/cifs/file.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact by setting the O_DIRECT flag during an attempt to open a file on a CIFS filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:29.695-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.691-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:31.199-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23616 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:13.457-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.586-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108819"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108915"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108482"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108755"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108878"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108526"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108735"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108547"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108768"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108574"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:108992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23615" version="81" class="patch">
      <metadata>
        <title>ELSA-2011:0282: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference ref_id="ELSA-2011:0282-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0282.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4422" ref_url="http://linux.oracle.com/cve/CVE-2010-4422.html" source="CVE"/>
        <reference ref_id="CVE-2010-4447" ref_url="http://linux.oracle.com/cve/CVE-2010-4447.html" source="CVE"/>
        <reference ref_id="CVE-2010-4448" ref_url="http://linux.oracle.com/cve/CVE-2010-4448.html" source="CVE"/>
        <reference ref_id="CVE-2010-4450" ref_url="http://linux.oracle.com/cve/CVE-2010-4450.html" source="CVE"/>
        <reference ref_id="CVE-2010-4451" ref_url="http://linux.oracle.com/cve/CVE-2010-4451.html" source="CVE"/>
        <reference ref_id="CVE-2010-4452" ref_url="http://linux.oracle.com/cve/CVE-2010-4452.html" source="CVE"/>
        <reference ref_id="CVE-2010-4454" ref_url="http://linux.oracle.com/cve/CVE-2010-4454.html" source="CVE"/>
        <reference ref_id="CVE-2010-4462" ref_url="http://linux.oracle.com/cve/CVE-2010-4462.html" source="CVE"/>
        <reference ref_id="CVE-2010-4463" ref_url="http://linux.oracle.com/cve/CVE-2010-4463.html" source="CVE"/>
        <reference ref_id="CVE-2010-4465" ref_url="http://linux.oracle.com/cve/CVE-2010-4465.html" source="CVE"/>
        <reference ref_id="CVE-2010-4466" ref_url="http://linux.oracle.com/cve/CVE-2010-4466.html" source="CVE"/>
        <reference ref_id="CVE-2010-4467" ref_url="http://linux.oracle.com/cve/CVE-2010-4467.html" source="CVE"/>
        <reference ref_id="CVE-2010-4468" ref_url="http://linux.oracle.com/cve/CVE-2010-4468.html" source="CVE"/>
        <reference ref_id="CVE-2010-4469" ref_url="http://linux.oracle.com/cve/CVE-2010-4469.html" source="CVE"/>
        <reference ref_id="CVE-2010-4470" ref_url="http://linux.oracle.com/cve/CVE-2010-4470.html" source="CVE"/>
        <reference ref_id="CVE-2010-4471" ref_url="http://linux.oracle.com/cve/CVE-2010-4471.html" source="CVE"/>
        <reference ref_id="CVE-2010-4472" ref_url="http://linux.oracle.com/cve/CVE-2010-4472.html" source="CVE"/>
        <reference ref_id="CVE-2010-4473" ref_url="http://linux.oracle.com/cve/CVE-2010-4473.html" source="CVE"/>
        <reference ref_id="CVE-2010-4475" ref_url="http://linux.oracle.com/cve/CVE-2010-4475.html" source="CVE"/>
        <reference ref_id="CVE-2010-4476" ref_url="http://linux.oracle.com/cve/CVE-2010-4476.html" source="CVE"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:33.033-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.236-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:30.899-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23615 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.505-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108216"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108372"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108533"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:107761"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108581"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108582"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108622"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108534"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108210"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108339"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108261"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108445"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23614" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0959: mutt security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mutt</product>
        </affected>
        <reference ref_id="ELSA-2011:0959-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0959.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1429" ref_url="http://linux.oracle.com/cve/CVE-2011-1429.html" source="CVE"/>
        <description>Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:19.339-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.174-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:30.792-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23614 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.795-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="mutt is earlier than 5:1.5.20-2.20091214hg736b6a.el6_1.1" test_ref="oval:org.mitre.oval:tst:108672"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23613" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1256: ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference ref_id="ELSA-2012:1256-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1256.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4405" ref_url="http://linux.oracle.com/cve/CVE-2012-4405.html" source="CVE"/>
        <description>Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow.  NOTE: this issue is also described as an array index error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:37.294-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:38.081-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:30.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23613 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:12.272-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:58.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:111009"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:110945"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:111043"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:110163"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:110911"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:110959"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:110704"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23612" version="41" class="patch">
      <metadata>
        <title>ELSA-2012:0729: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2012:0729-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0729.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1711" ref_url="http://linux.oracle.com/cve/CVE-2012-1711.html" source="CVE"/>
        <reference ref_id="CVE-2012-1713" ref_url="http://linux.oracle.com/cve/CVE-2012-1713.html" source="CVE"/>
        <reference ref_id="CVE-2012-1716" ref_url="http://linux.oracle.com/cve/CVE-2012-1716.html" source="CVE"/>
        <reference ref_id="CVE-2012-1717" ref_url="http://linux.oracle.com/cve/CVE-2012-1717.html" source="CVE"/>
        <reference ref_id="CVE-2012-1718" ref_url="http://linux.oracle.com/cve/CVE-2012-1718.html" source="CVE"/>
        <reference ref_id="CVE-2012-1719" ref_url="http://linux.oracle.com/cve/CVE-2012-1719.html" source="CVE"/>
        <reference ref_id="CVE-2012-1723" ref_url="http://linux.oracle.com/cve/CVE-2012-1723.html" source="CVE"/>
        <reference ref_id="CVE-2012-1724" ref_url="http://linux.oracle.com/cve/CVE-2012-1724.html" source="CVE"/>
        <reference ref_id="CVE-2012-1725" ref_url="http://linux.oracle.com/cve/CVE-2012-1725.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:30.735-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:37.865-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:30.243-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23612 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:07.521-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:57.861-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:110306"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:109886"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:110474"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:110258"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:110296"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23611" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1819: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference ref_id="ELSA-2011:1819-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1819.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4539" ref_url="http://linux.oracle.com/cve/CVE-2011-4539.html" source="CVE"/>
        <description>dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:16.487-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:37.800-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:30.128-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23611 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.384-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:57.769-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="dhcp-devel is earlier than 12:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:109686"/>
          <criterion comment="dhclient is earlier than 12:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:109671"/>
          <criterion comment="dhcp is earlier than 12:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:109388"/>
          <criterion comment="dhcp-common is earlier than 12:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:109493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23610" version="33" class="patch">
      <metadata>
        <title>ELSA-2012:0469: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2012:0469-03" ref_url="http://linux.oracle.com/errata/ELSA-2012-0469.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4370" ref_url="http://linux.oracle.com/cve/CVE-2011-4370.html" source="CVE"/>
        <reference ref_id="CVE-2011-4371" ref_url="http://linux.oracle.com/cve/CVE-2011-4371.html" source="CVE"/>
        <reference ref_id="CVE-2011-4372" ref_url="http://linux.oracle.com/cve/CVE-2011-4372.html" source="CVE"/>
        <reference ref_id="CVE-2011-4373" ref_url="http://linux.oracle.com/cve/CVE-2011-4373.html" source="CVE"/>
        <reference ref_id="CVE-2012-0774" ref_url="http://linux.oracle.com/cve/CVE-2012-0774.html" source="CVE"/>
        <reference ref_id="CVE-2012-0775" ref_url="http://linux.oracle.com/cve/CVE-2012-0775.html" source="CVE"/>
        <reference ref_id="CVE-2012-0777" ref_url="http://linux.oracle.com/cve/CVE-2012-0777.html" source="CVE"/>
        <description>The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:18.126-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:37.618-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:29.735-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23610 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:05.707-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:57.502-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:110135"/>
            <criterion comment="acroread is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:109594"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:109448"/>
            <criterion comment="acroread is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:109981"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23609" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1123: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:1123-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1123.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3817" ref_url="http://linux.oracle.com/cve/CVE-2012-3817.html" source="CVE"/>
        <description>ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:38.071-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:37.524-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:29.597-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23609 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:07.896-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:57.335-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110762"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110530"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110424"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110498"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110806"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110773"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:109825"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:110241"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110731"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110819"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110772"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110619"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110464"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:110496"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23608" version="21" class="patch">
      <metadata>
        <title>ELSA-2011:1083: fuse security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>fuse</product>
        </affected>
        <reference ref_id="ELSA-2011:1083-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1083.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3879" ref_url="http://linux.oracle.com/cve/CVE-2010-3879.html" source="CVE"/>
        <reference ref_id="CVE-2011-0541" ref_url="http://linux.oracle.com/cve/CVE-2011-0541.html" source="CVE"/>
        <reference ref_id="CVE-2011-0542" ref_url="http://linux.oracle.com/cve/CVE-2011-0542.html" source="CVE"/>
        <reference ref_id="CVE-2011-0543" ref_url="http://linux.oracle.com/cve/CVE-2011-0543.html" source="CVE"/>
        <description>Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:24.682-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:37.402-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:29.378-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23608 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:16.126-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:57.157-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="fuse-devel is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:108994"/>
          <criterion comment="fuse-libs is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:109040"/>
          <criterion comment="fuse is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:108965"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23607" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0844: apr security update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference ref_id="ELSA-2011:0844-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0844.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1928" ref_url="http://linux.oracle.com/cve/CVE-2011-1928.html" source="CVE"/>
        <description>The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used.  NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:40.980-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:37.327-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:29.260-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23607 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:14.885-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:57.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:108649"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:109008"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:108834"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:108912"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:108886"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23606" version="69" class="patch">
      <metadata>
        <title>ELSA-2010:0873: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2010:0873-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0873.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1321" ref_url="http://linux.oracle.com/cve/CVE-2010-1321.html" source="CVE"/>
        <reference ref_id="CVE-2010-3541" ref_url="http://linux.oracle.com/cve/CVE-2010-3541.html" source="CVE"/>
        <reference ref_id="CVE-2010-3548" ref_url="http://linux.oracle.com/cve/CVE-2010-3548.html" source="CVE"/>
        <reference ref_id="CVE-2010-3549" ref_url="http://linux.oracle.com/cve/CVE-2010-3549.html" source="CVE"/>
        <reference ref_id="CVE-2010-3550" ref_url="http://linux.oracle.com/cve/CVE-2010-3550.html" source="CVE"/>
        <reference ref_id="CVE-2010-3551" ref_url="http://linux.oracle.com/cve/CVE-2010-3551.html" source="CVE"/>
        <reference ref_id="CVE-2010-3556" ref_url="http://linux.oracle.com/cve/CVE-2010-3556.html" source="CVE"/>
        <reference ref_id="CVE-2010-3559" ref_url="http://linux.oracle.com/cve/CVE-2010-3559.html" source="CVE"/>
        <reference ref_id="CVE-2010-3562" ref_url="http://linux.oracle.com/cve/CVE-2010-3562.html" source="CVE"/>
        <reference ref_id="CVE-2010-3565" ref_url="http://linux.oracle.com/cve/CVE-2010-3565.html" source="CVE"/>
        <reference ref_id="CVE-2010-3566" ref_url="http://linux.oracle.com/cve/CVE-2010-3566.html" source="CVE"/>
        <reference ref_id="CVE-2010-3568" ref_url="http://linux.oracle.com/cve/CVE-2010-3568.html" source="CVE"/>
        <reference ref_id="CVE-2010-3569" ref_url="http://linux.oracle.com/cve/CVE-2010-3569.html" source="CVE"/>
        <reference ref_id="CVE-2010-3572" ref_url="http://linux.oracle.com/cve/CVE-2010-3572.html" source="CVE"/>
        <reference ref_id="CVE-2010-3573" ref_url="http://linux.oracle.com/cve/CVE-2010-3573.html" source="CVE"/>
        <reference ref_id="CVE-2010-3574" ref_url="http://linux.oracle.com/cve/CVE-2010-3574.html" source="CVE"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:36.776-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.986-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:28.937-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23606 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:12.647-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:56.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108193"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:107639"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108200"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:107836"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108084"/>
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108229"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108107"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23605" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1533: ipa security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ipa</product>
        </affected>
        <reference ref_id="ELSA-2011:1533-04" ref_url="http://linux.oracle.com/errata/ELSA-2011-1533.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3636" ref_url="http://linux.oracle.com/cve/CVE-2011-3636.html" source="CVE"/>
        <description>Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authentication of administrators for requests that make configuration changes.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:01.869-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.913-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:28.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23605 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:09.255-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:56.651-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ipa-python is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:109661"/>
          <criterion comment="ipa-admintools is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:109512"/>
          <criterion comment="ipa-client is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:109672"/>
          <criterion comment="ipa-server-selinux is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:109614"/>
          <criterion comment="ipa-server is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:109640"/>
          <criterion comment="ipa is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:109166"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23603" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:1569: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:1569-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1569.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5676" ref_url="http://linux.oracle.com/cve/CVE-2012-5676.html" source="CVE"/>
        <reference ref_id="CVE-2012-5677" ref_url="http://linux.oracle.com/cve/CVE-2012-5677.html" source="CVE"/>
        <reference ref_id="CVE-2012-5678" ref_url="http://linux.oracle.com/cve/CVE-2012-5678.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on Mac OS X, before 10.3.183.48 and 11.x before 11.2.202.258 on Linux, before 11.1.111.29 on Android 2.x and 3.x, and before 11.1.115.34 on Android 4.x; Adobe AIR before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X; and Adobe AIR SDK before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:11.478-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.748-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:28.551-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23603 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:15.903-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:56.411-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.258-1.el6" test_ref="oval:org.mitre.oval:tst:111147"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23601" version="45" class="patch">
      <metadata>
        <title>ELSA-2011:0938: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0938-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0938.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0802" ref_url="http://linux.oracle.com/cve/CVE-2011-0802.html" source="CVE"/>
        <reference ref_id="CVE-2011-0814" ref_url="http://linux.oracle.com/cve/CVE-2011-0814.html" source="CVE"/>
        <reference ref_id="CVE-2011-0862" ref_url="http://linux.oracle.com/cve/CVE-2011-0862.html" source="CVE"/>
        <reference ref_id="CVE-2011-0863" ref_url="http://linux.oracle.com/cve/CVE-2011-0863.html" source="CVE"/>
        <reference ref_id="CVE-2011-0865" ref_url="http://linux.oracle.com/cve/CVE-2011-0865.html" source="CVE"/>
        <reference ref_id="CVE-2011-0867" ref_url="http://linux.oracle.com/cve/CVE-2011-0867.html" source="CVE"/>
        <reference ref_id="CVE-2011-0868" ref_url="http://linux.oracle.com/cve/CVE-2011-0868.html" source="CVE"/>
        <reference ref_id="CVE-2011-0869" ref_url="http://linux.oracle.com/cve/CVE-2011-0869.html" source="CVE"/>
        <reference ref_id="CVE-2011-0871" ref_url="http://linux.oracle.com/cve/CVE-2011-0871.html" source="CVE"/>
        <reference ref_id="CVE-2011-0873" ref_url="http://linux.oracle.com/cve/CVE-2011-0873.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:19.928-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.482-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:27.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23601 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:05.858-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:56.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109059"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109088"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108969"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109042"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109154"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109117"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108648"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:109094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109035"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109019"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109013"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109111"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109084"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:109085"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108219"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23600" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0464: kdelibs security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kdelibs</product>
        </affected>
        <reference ref_id="ELSA-2011:0464-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0464.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1094" ref_url="http://linux.oracle.com/cve/CVE-2011-1094.html" source="CVE"/>
        <reference ref_id="CVE-2011-1168" ref_url="http://linux.oracle.com/cve/CVE-2011-1168.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in the KHTMLPart::htmlError function in khtml/khtml_part.cpp in Konqueror in KDE SC 4.4.0 through 4.6.1 allows remote attackers to inject arbitrary web script or HTML via the URI in a URL corresponding to an unavailable web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:44.075-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.390-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:27.666-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23600 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:08.936-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:55.910-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kdelibs-apidocs is earlier than 6:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:108852"/>
          <criterion comment="kdelibs-common is earlier than 6:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:108376"/>
          <criterion comment="kdelibs-devel is earlier than 6:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:108836"/>
          <criterion comment="kdelibs is earlier than 6:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:108141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23599" version="37" class="patch">
      <metadata>
        <title>ELSA-2010:0896: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2010:0896-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0896.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3175" ref_url="http://linux.oracle.com/cve/CVE-2010-3175.html" source="CVE"/>
        <reference ref_id="CVE-2010-3176" ref_url="http://linux.oracle.com/cve/CVE-2010-3176.html" source="CVE"/>
        <reference ref_id="CVE-2010-3178" ref_url="http://linux.oracle.com/cve/CVE-2010-3178.html" source="CVE"/>
        <reference ref_id="CVE-2010-3179" ref_url="http://linux.oracle.com/cve/CVE-2010-3179.html" source="CVE"/>
        <reference ref_id="CVE-2010-3180" ref_url="http://linux.oracle.com/cve/CVE-2010-3180.html" source="CVE"/>
        <reference ref_id="CVE-2010-3182" ref_url="http://linux.oracle.com/cve/CVE-2010-3182.html" source="CVE"/>
        <reference ref_id="CVE-2010-3183" ref_url="http://linux.oracle.com/cve/CVE-2010-3183.html" source="CVE"/>
        <reference ref_id="CVE-2010-3765" ref_url="http://linux.oracle.com/cve/CVE-2010-3765.html" source="CVE"/>
        <description>Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:27.305-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.197-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:27.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23599 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:13.608-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:55.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.6-1.el6_0" test_ref="oval:org.mitre.oval:tst:108288"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23598" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0359: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:0359-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0359.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0768" ref_url="http://linux.oracle.com/cve/CVE-2012-0768.html" source="CVE"/>
        <reference ref_id="CVE-2012-0769" ref_url="http://linux.oracle.com/cve/CVE-2012-0769.html" source="CVE"/>
        <description>Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x does not properly handle integers, which allows attackers to obtain sensitive information via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:10.977-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:36.070-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:27.128-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23598 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:11.593-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:55.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.16-1.el5" test_ref="oval:org.mitre.oval:tst:109164"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.16-1.el6" test_ref="oval:org.mitre.oval:tst:109970"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23597" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0627: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0627-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0627.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0787" ref_url="http://linux.oracle.com/cve/CVE-2013-0787.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:40.170-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:35.965-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:27.016-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23597 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:10.120-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:55.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:111449"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:111675"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23596" version="177" class="patch">
      <metadata>
        <title>ELSA-2013:1060: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:1060-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1060.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2400" ref_url="http://linux.oracle.com/cve/CVE-2013-2400.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2437" ref_url="http://linux.oracle.com/cve/CVE-2013-2437.html" source="CVE"/>
        <reference ref_id="CVE-2013-2442" ref_url="http://linux.oracle.com/cve/CVE-2013-2442.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2449" ref_url="http://linux.oracle.com/cve/CVE-2013-2449.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2451" ref_url="http://linux.oracle.com/cve/CVE-2013-2451.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2454" ref_url="http://linux.oracle.com/cve/CVE-2013-2454.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2458" ref_url="http://linux.oracle.com/cve/CVE-2013-2458.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2460" ref_url="http://linux.oracle.com/cve/CVE-2013-2460.html" source="CVE"/>
        <reference ref_id="CVE-2013-2462" ref_url="http://linux.oracle.com/cve/CVE-2013-2462.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2464" ref_url="http://linux.oracle.com/cve/CVE-2013-2464.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2466" ref_url="http://linux.oracle.com/cve/CVE-2013-2466.html" source="CVE"/>
        <reference ref_id="CVE-2013-2468" ref_url="http://linux.oracle.com/cve/CVE-2013-2468.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <reference ref_id="CVE-2013-3006" ref_url="http://linux.oracle.com/cve/CVE-2013-3006.html" source="CVE"/>
        <reference ref_id="CVE-2013-3007" ref_url="http://linux.oracle.com/cve/CVE-2013-3007.html" source="CVE"/>
        <reference ref_id="CVE-2013-3008" ref_url="http://linux.oracle.com/cve/CVE-2013-3008.html" source="CVE"/>
        <reference ref_id="CVE-2013-3009" ref_url="http://linux.oracle.com/cve/CVE-2013-3009.html" source="CVE"/>
        <reference ref_id="CVE-2013-3010" ref_url="http://linux.oracle.com/cve/CVE-2013-3010.html" source="CVE"/>
        <reference ref_id="CVE-2013-3011" ref_url="http://linux.oracle.com/cve/CVE-2013-3011.html" source="CVE"/>
        <reference ref_id="CVE-2013-3012" ref_url="http://linux.oracle.com/cve/CVE-2013-3012.html" source="CVE"/>
        <reference ref_id="CVE-2013-3744" ref_url="http://linux.oracle.com/cve/CVE-2013-3744.html" source="CVE"/>
        <reference ref_id="CVE-2013-4002" ref_url="http://linux.oracle.com/cve/CVE-2013-4002.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:03.415-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:35.059-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:25.311-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23596 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:15.727-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:54.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111976"/>
          <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:112224"/>
          <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:112334"/>
          <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:112344"/>
          <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111511"/>
          <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23595" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0291: java-1.5.0-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0291-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0291.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4476" ref_url="http://linux.oracle.com/cve/CVE-2010-4476.html" source="CVE"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:41.057-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.968-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:25.170-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23595 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:11.913-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:54.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108414"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108691"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108217"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108564"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108635"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108463"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108679"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:108601"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108682"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108083"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108545"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108527"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108535"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108074"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:108243"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23594" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1801: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2011:1801-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1801.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4111" ref_url="http://linux.oracle.com/cve/CVE-2011-4111.html" source="CVE"/>
        <description>Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:00.015-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.899-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:25.061-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23594 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:13.933-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:54.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6_1.9" test_ref="oval:org.mitre.oval:tst:109062"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6_1.9" test_ref="oval:org.mitre.oval:tst:109610"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6_1.9" test_ref="oval:org.mitre.oval:tst:109654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23593" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0305: samba security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2011:0305-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0305.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0719" ref_url="http://linux.oracle.com/cve/CVE-2011-0719.html" source="CVE"/>
        <description>Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:20.783-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.822-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:24.908-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23593 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:06.072-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:53.948-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="samba-client is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108310"/>
          <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108620"/>
          <criterion comment="samba is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108696"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108226"/>
          <criterion comment="samba-winbind is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108499"/>
          <criterion comment="samba-doc is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108677"/>
          <criterion comment="samba-common is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108162"/>
          <criterion comment="samba-winbind-clients is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108726"/>
          <criterion comment="samba-winbind-devel is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108368"/>
          <criterion comment="samba-swat is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:107742"/>
          <criterion comment="libsmbclient is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:108583"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23592" version="57" class="patch">
      <metadata>
        <title>ELSA-2011:0357: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0357-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0357.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4422" ref_url="http://linux.oracle.com/cve/CVE-2010-4422.html" source="CVE"/>
        <reference ref_id="CVE-2010-4447" ref_url="http://linux.oracle.com/cve/CVE-2010-4447.html" source="CVE"/>
        <reference ref_id="CVE-2010-4448" ref_url="http://linux.oracle.com/cve/CVE-2010-4448.html" source="CVE"/>
        <reference ref_id="CVE-2010-4452" ref_url="http://linux.oracle.com/cve/CVE-2010-4452.html" source="CVE"/>
        <reference ref_id="CVE-2010-4454" ref_url="http://linux.oracle.com/cve/CVE-2010-4454.html" source="CVE"/>
        <reference ref_id="CVE-2010-4462" ref_url="http://linux.oracle.com/cve/CVE-2010-4462.html" source="CVE"/>
        <reference ref_id="CVE-2010-4463" ref_url="http://linux.oracle.com/cve/CVE-2010-4463.html" source="CVE"/>
        <reference ref_id="CVE-2010-4465" ref_url="http://linux.oracle.com/cve/CVE-2010-4465.html" source="CVE"/>
        <reference ref_id="CVE-2010-4466" ref_url="http://linux.oracle.com/cve/CVE-2010-4466.html" source="CVE"/>
        <reference ref_id="CVE-2010-4467" ref_url="http://linux.oracle.com/cve/CVE-2010-4467.html" source="CVE"/>
        <reference ref_id="CVE-2010-4468" ref_url="http://linux.oracle.com/cve/CVE-2010-4468.html" source="CVE"/>
        <reference ref_id="CVE-2010-4471" ref_url="http://linux.oracle.com/cve/CVE-2010-4471.html" source="CVE"/>
        <reference ref_id="CVE-2010-4473" ref_url="http://linux.oracle.com/cve/CVE-2010-4473.html" source="CVE"/>
        <reference ref_id="CVE-2010-4475" ref_url="http://linux.oracle.com/cve/CVE-2010-4475.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:17.499-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.504-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:24.614-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23592 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:13.188-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:53.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108725"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108518"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108713"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108508"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108699"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108515"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108289"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108523"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108704"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108552"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108068"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108690"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108600"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108447"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108454"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23591" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1869: pixman security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference ref_id="ELSA-2013:1869-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1869.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6425" ref_url="http://linux.oracle.com/cve/CVE-2013-6425.html" source="CVE"/>
        <description>Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:35.781-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.435-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:24.472-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23591 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:15.233-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:53.551-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:53:07.736-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:53:07.736-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pixman-devel is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:107640"/>
            <criterion comment="pixman is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:107988"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="pixman-devel is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:107555"/>
            <criterion comment="pixman is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:107351"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23590" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0093: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0093-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0093.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0830" ref_url="http://linux.oracle.com/cve/CVE-2012-0830.html" source="CVE"/>
        <description>The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.	 NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:12.470-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.285-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:24.248-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23590 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:06.897-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:53.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109884"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109173"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109747"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109806"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109809"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109937"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109902"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109634"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109523"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109830"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109966"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109684"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109733"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109957"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109627"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109103"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109846"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109898"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109897"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109731"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109974"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109896"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:110007"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109350"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109979"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:109932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109687"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109722"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109962"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109808"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109856"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109987"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109544"/>
            <criterion comment="php is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:110037"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109847"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109626"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109324"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109844"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109917"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109968"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109703"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109411"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:110104"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109397"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:109953"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23589" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0019: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0019-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0019.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4566" ref_url="http://linux.oracle.com/cve/CVE-2011-4566.html" source="CVE"/>
        <reference ref_id="CVE-2011-4885" ref_url="http://linux.oracle.com/cve/CVE-2011-4885.html" source="CVE"/>
        <description>PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:20.328-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:34.125-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:23.965-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23589 - optimisation of Oracle Linux content" date="2014-05-05T17:32:00.187-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:34:06.244-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:53.091-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109570"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:108792"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109696"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109287"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109432"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109601"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109139"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109217"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109469"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109668"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109477"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109595"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109021"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109706"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109118"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109768"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109574"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109739"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:108978"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109549"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109447"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109587"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109685"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109357"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109437"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:109773"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109717"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109732"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109378"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109200"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109766"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109068"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109566"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109730"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109611"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109620"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109757"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109532"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109214"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109541"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109522"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109771"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:108870"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109195"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109445"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109608"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:109756"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23588" version="61" class="patch">
      <metadata>
        <title>ELSA-2012:1346: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2012:1346-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1346.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5248" ref_url="http://linux.oracle.com/cve/CVE-2012-5248.html" source="CVE"/>
        <reference ref_id="CVE-2012-5249" ref_url="http://linux.oracle.com/cve/CVE-2012-5249.html" source="CVE"/>
        <reference ref_id="CVE-2012-5250" ref_url="http://linux.oracle.com/cve/CVE-2012-5250.html" source="CVE"/>
        <reference ref_id="CVE-2012-5251" ref_url="http://linux.oracle.com/cve/CVE-2012-5251.html" source="CVE"/>
        <reference ref_id="CVE-2012-5252" ref_url="http://linux.oracle.com/cve/CVE-2012-5252.html" source="CVE"/>
        <reference ref_id="CVE-2012-5253" ref_url="http://linux.oracle.com/cve/CVE-2012-5253.html" source="CVE"/>
        <reference ref_id="CVE-2012-5254" ref_url="http://linux.oracle.com/cve/CVE-2012-5254.html" source="CVE"/>
        <reference ref_id="CVE-2012-5255" ref_url="http://linux.oracle.com/cve/CVE-2012-5255.html" source="CVE"/>
        <reference ref_id="CVE-2012-5256" ref_url="http://linux.oracle.com/cve/CVE-2012-5256.html" source="CVE"/>
        <reference ref_id="CVE-2012-5257" ref_url="http://linux.oracle.com/cve/CVE-2012-5257.html" source="CVE"/>
        <reference ref_id="CVE-2012-5258" ref_url="http://linux.oracle.com/cve/CVE-2012-5258.html" source="CVE"/>
        <reference ref_id="CVE-2012-5259" ref_url="http://linux.oracle.com/cve/CVE-2012-5259.html" source="CVE"/>
        <reference ref_id="CVE-2012-5260" ref_url="http://linux.oracle.com/cve/CVE-2012-5260.html" source="CVE"/>
        <reference ref_id="CVE-2012-5261" ref_url="http://linux.oracle.com/cve/CVE-2012-5261.html" source="CVE"/>
        <reference ref_id="CVE-2012-5262" ref_url="http://linux.oracle.com/cve/CVE-2012-5262.html" source="CVE"/>
        <reference ref_id="CVE-2012-5263" ref_url="http://linux.oracle.com/cve/CVE-2012-5263.html" source="CVE"/>
        <reference ref_id="CVE-2012-5264" ref_url="http://linux.oracle.com/cve/CVE-2012-5264.html" source="CVE"/>
        <reference ref_id="CVE-2012-5265" ref_url="http://linux.oracle.com/cve/CVE-2012-5265.html" source="CVE"/>
        <reference ref_id="CVE-2012-5266" ref_url="http://linux.oracle.com/cve/CVE-2012-5266.html" source="CVE"/>
        <reference ref_id="CVE-2012-5267" ref_url="http://linux.oracle.com/cve/CVE-2012-5267.html" source="CVE"/>
        <reference ref_id="CVE-2012-5268" ref_url="http://linux.oracle.com/cve/CVE-2012-5268.html" source="CVE"/>
        <reference ref_id="CVE-2012-5269" ref_url="http://linux.oracle.com/cve/CVE-2012-5269.html" source="CVE"/>
        <reference ref_id="CVE-2012-5270" ref_url="http://linux.oracle.com/cve/CVE-2012-5270.html" source="CVE"/>
        <reference ref_id="CVE-2012-5271" ref_url="http://linux.oracle.com/cve/CVE-2012-5271.html" source="CVE"/>
        <reference ref_id="CVE-2012-5272" ref_url="http://linux.oracle.com/cve/CVE-2012-5272.html" source="CVE"/>
        <reference ref_id="CVE-2012-5285" ref_url="http://linux.oracle.com/cve/CVE-2012-5285.html" source="CVE"/>
        <reference ref_id="CVE-2012-5286" ref_url="http://linux.oracle.com/cve/CVE-2012-5286.html" source="CVE"/>
        <reference ref_id="CVE-2012-5287" ref_url="http://linux.oracle.com/cve/CVE-2012-5287.html" source="CVE"/>
        <reference ref_id="CVE-2012-5673" ref_url="http://linux.oracle.com/cve/CVE-2012-5673.html" source="CVE"/>
        <description>Unspecified vulnerability in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 has unknown impact and attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:06.697-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:33.539-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:22.784-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23588 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:17.193-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:59.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.243-1.el6" test_ref="oval:org.mitre.oval:tst:110995"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23586" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0506: rdesktop security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>rdesktop</product>
        </affected>
        <reference ref_id="ELSA-2011:0506-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0506.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1595" ref_url="http://linux.oracle.com/cve/CVE-2011-1595.html" source="CVE"/>
        <description>Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:27.671-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.901-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:21.558-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23586 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.520-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:52.198-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="rdesktop is earlier than 0:1.6.0-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:108592"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23585" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0923: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference ref_id="ELSA-2010:0923-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0923.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3611" ref_url="http://linux.oracle.com/cve/CVE-2010-3611.html" source="CVE"/>
        <description>ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a Relay-Forward message without an address in the Relay-Forward link-address field.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:31.893-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.832-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:21.449-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23585 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:57.398-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:52.036-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108060"/>
          <criterion comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.1" test_ref="oval:org.mitre.oval:tst:107597"/>
          <criterion comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23583" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0258: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference ref_id="ELSA-2011:0258-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0258.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3315" ref_url="http://linux.oracle.com/cve/CVE-2010-3315.html" source="CVE"/>
        <reference ref_id="CVE-2010-4539" ref_url="http://linux.oracle.com/cve/CVE-2010-4539.html" source="CVE"/>
        <reference ref_id="CVE-2010-4644" ref_url="http://linux.oracle.com/cve/CVE-2010-4644.html" source="CVE"/>
        <description>Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:18.528-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.715-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:21.243-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23583 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:56.884-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:51.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:108448"/>
          <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:108425"/>
          <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:108617"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:108442"/>
          <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:108396"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:108338"/>
          <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:108457"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:108477"/>
          <criterion comment="subversion is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:108184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23582" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0919: qemu-kvm security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2011:0919-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0919.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2212" ref_url="http://linux.oracle.com/cve/CVE-2011-2212.html" source="CVE"/>
        <reference ref_id="CVE-2011-2512" ref_url="http://linux.oracle.com/cve/CVE-2011-2512.html" source="CVE"/>
        <description>The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and possibly execute arbitrary code via a negative number in the Queue Notify field of the Virtio Header, which bypasses a signed comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:23.403-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.617-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:21.095-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23582 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.285-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:51.735-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6_1.2" test_ref="oval:org.mitre.oval:tst:108670"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6_1.2" test_ref="oval:org.mitre.oval:tst:109022"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6_1.2" test_ref="oval:org.mitre.oval:tst:109126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23581" version="5" class="patch">
      <metadata>
        <title>ELSA-2013:1866: ca-certificates security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ca-certificates</product>
        </affected>
        <reference ref_id="ELSA-2013:1866-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1866.html" source="VENDOR"/>
        <description>This package contains the set of CA certificates chosen by the Mozilla
Foundation for use with the Internet Public Key Infrastructure (PKI).
It was found that a subordinate Certificate Authority (CA) mis-issued an
intermediate certificate, which could be used to conduct man-in-the-middle
attacks. This update renders that particular intermediate certificate as
untrusted. (BZ#1038894)
All users should upgrade to this updated package. After installing the
update, all applications using the ca-certificates package must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:07.345-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.577-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:21.033-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23581 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:57.703-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:51.644-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="ca-certificates is earlier than 0:2013.1.95-65.1.el6_5" test_ref="oval:org.mitre.oval:tst:112678"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23580" version="41" class="patch">
      <metadata>
        <title>ELSA-2013:1823: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1823-04" ref_url="http://linux.oracle.com/errata/ELSA-2013-1823.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0772" ref_url="http://linux.oracle.com/cve/CVE-2013-0772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5609" ref_url="http://linux.oracle.com/cve/CVE-2013-5609.html" source="CVE"/>
        <reference ref_id="CVE-2013-5612" ref_url="http://linux.oracle.com/cve/CVE-2013-5612.html" source="CVE"/>
        <reference ref_id="CVE-2013-5613" ref_url="http://linux.oracle.com/cve/CVE-2013-5613.html" source="CVE"/>
        <reference ref_id="CVE-2013-5614" ref_url="http://linux.oracle.com/cve/CVE-2013-5614.html" source="CVE"/>
        <reference ref_id="CVE-2013-5616" ref_url="http://linux.oracle.com/cve/CVE-2013-5616.html" source="CVE"/>
        <reference ref_id="CVE-2013-5618" ref_url="http://linux.oracle.com/cve/CVE-2013-5618.html" source="CVE"/>
        <reference ref_id="CVE-2013-6671" ref_url="http://linux.oracle.com/cve/CVE-2013-6671.html" source="CVE"/>
        <reference ref_id="CVE-2013-6674" ref_url="http://linux.oracle.com/cve/CVE-2013-6674.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:24.585-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.360-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:20.619-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23580 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:55.957-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:51.343-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:108018"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:107576"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23579" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1263: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:1263-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1263.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3488" ref_url="http://linux.oracle.com/cve/CVE-2012-3488.html" source="CVE"/>
        <reference ref_id="CVE-2012-3489" ref_url="http://linux.oracle.com/cve/CVE-2012-3489.html" source="CVE"/>
        <description>The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:40.637-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.237-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:20.414-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23579 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:56.295-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:51.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111177"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110965"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110291"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111129"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111058"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111182"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111088"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110802"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111077"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110850"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:111192"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:110818"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110553"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111062"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111206"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110844"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111028"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110791"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111044"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:111163"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110706"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:110699"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23578" version="21" class="patch">
      <metadata>
        <title>ELSA-2011:0009: evince security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>evince</product>
        </affected>
        <reference ref_id="ELSA-2011:0009-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0009.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2640" ref_url="http://linux.oracle.com/cve/CVE-2010-2640.html" source="CVE"/>
        <reference ref_id="CVE-2010-2641" ref_url="http://linux.oracle.com/cve/CVE-2010-2641.html" source="CVE"/>
        <reference ref_id="CVE-2010-2642" ref_url="http://linux.oracle.com/cve/CVE-2010-2642.html" source="CVE"/>
        <reference ref_id="CVE-2010-2643" ref_url="http://linux.oracle.com/cve/CVE-2010-2643.html" source="CVE"/>
        <description>Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:21.264-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.122-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:20.174-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23578 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:57.303-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:50.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="evince is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:108264"/>
          <criterion comment="evince-libs is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:107855"/>
          <criterion comment="evince-devel is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:108292"/>
          <criterion comment="evince-dvi is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:107588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23577" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0590: nss-pam-ldapd security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>nss-pam-ldapd</product>
        </affected>
        <reference ref_id="ELSA-2013:0590-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0590.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0288" ref_url="http://linux.oracle.com/cve/CVE-2013-0288.html" source="CVE"/>
        <description>nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:35.264-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:32.063-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:20.073-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23577 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.185-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:50.874-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="nss-pam-ldapd is earlier than 0:0.7.5-18.1.el6_4" test_ref="oval:org.mitre.oval:tst:110990"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23576" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0550: bind security and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2013:0550-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0550.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5689" ref_url="http://linux.oracle.com/cve/CVE-2012-5689.html" source="CVE"/>
        <description>ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:35.013-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:31.997-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:19.952-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23576 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.694-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:50.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:111630"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:111523"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:111556"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:111401"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:110763"/>
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:111577"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23575" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1861: nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>nss</product>
        </affected>
        <reference ref_id="ELSA-2013:1861-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1861.html" source="VENDOR"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.
It was found that a subordinate Certificate Authority (CA) mis-issued an
intermediate certificate, which could be used to conduct man-in-the-middle
attacks. This update renders that particular intermediate certificate as
untrusted. (BZ#1038894)
Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.
All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:29.558-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:31.941-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:19.847-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23575 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:54.032-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:50.558-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:52:29.946-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:52:29.946-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:107952"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:107397"/>
            <criterion comment="nss is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:108047"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:107994"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="nss-tools is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107669"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107898"/>
            <criterion comment="nss-sysinit is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107724"/>
            <criterion comment="nss is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107729"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:107937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23574" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1243: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1243-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1243.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Thunderbird; however, affected certificates
issued after this date cannot be re-enabled or used. (BZ#734316)
All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:10.734-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:31.895-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:19.771-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23574 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:55.324-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:50.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-24.el5" test_ref="oval:org.mitre.oval:tst:109333"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:3.1.12-2.el6_1" test_ref="oval:org.mitre.oval:tst:109183"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23573" version="49" class="patch">
      <metadata>
        <title>ELSA-2011:0310: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:0310-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0310.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1585" ref_url="http://linux.oracle.com/cve/CVE-2010-1585.html" source="CVE"/>
        <reference ref_id="CVE-2011-0051" ref_url="http://linux.oracle.com/cve/CVE-2011-0051.html" source="CVE"/>
        <reference ref_id="CVE-2011-0053" ref_url="http://linux.oracle.com/cve/CVE-2011-0053.html" source="CVE"/>
        <reference ref_id="CVE-2011-0054" ref_url="http://linux.oracle.com/cve/CVE-2011-0054.html" source="CVE"/>
        <reference ref_id="CVE-2011-0055" ref_url="http://linux.oracle.com/cve/CVE-2011-0055.html" source="CVE"/>
        <reference ref_id="CVE-2011-0056" ref_url="http://linux.oracle.com/cve/CVE-2011-0056.html" source="CVE"/>
        <reference ref_id="CVE-2011-0057" ref_url="http://linux.oracle.com/cve/CVE-2011-0057.html" source="CVE"/>
        <reference ref_id="CVE-2011-0058" ref_url="http://linux.oracle.com/cve/CVE-2011-0058.html" source="CVE"/>
        <reference ref_id="CVE-2011-0059" ref_url="http://linux.oracle.com/cve/CVE-2011-0059.html" source="CVE"/>
        <reference ref_id="CVE-2011-0061" ref_url="http://linux.oracle.com/cve/CVE-2011-0061.html" source="CVE"/>
        <reference ref_id="CVE-2011-0062" ref_url="http://linux.oracle.com/cve/CVE-2011-0062.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:31.268-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:31.560-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:19.284-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23573 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:55.555-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:50.058-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:108688"/>
          <criterion comment="xulrunner is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:108655"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:108688"/>
          <criterion comment="xulrunner is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:108655"/>
          <criterion comment="firefox is earlier than 0:3.6.14-4.el6_0" test_ref="oval:org.mitre.oval:tst:108707"/>
          <criterion comment="firefox is earlier than 0:3.6.14-4.el6_0" test_ref="oval:org.mitre.oval:tst:108707"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23572" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0616: pidgin security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2011:0616-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0616.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1091" ref_url="http://linux.oracle.com/cve/CVE-2011-1091.html" source="CVE"/>
        <reference ref_id="CVE-2011-4922" ref_url="http://linux.oracle.com/cve/CVE-2011-4922.html" source="CVE"/>
        <description>cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:36.567-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:31.411-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:19.123-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23572 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:55.699-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:49.920-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pidgin-docs is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108901"/>
          <criterion comment="pidgin-perl is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108692"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108989"/>
          <criterion comment="libpurple is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108604"/>
          <criterion comment="finch-devel is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108621"/>
          <criterion comment="libpurple-perl is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108975"/>
          <criterion comment="finch is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108061"/>
          <criterion comment="libpurple-devel is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108942"/>
          <criterion comment="pidgin-devel is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108861"/>
          <criterion comment="pidgin is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:108894"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23571" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0507: apr security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference ref_id="ELSA-2011:0507-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0507.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0419" ref_url="http://linux.oracle.com/cve/CVE-2011-0419.html" source="CVE"/>
        <description>Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:36.997-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:31.303-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:18.931-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23571 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.408-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:49.791-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:107865"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:108362"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:108785"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108409"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108847"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23570" version="42" class="patch">
      <metadata>
        <title>ELSA-2011:0364: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0364-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0364.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4447" ref_url="http://linux.oracle.com/cve/CVE-2010-4447.html" source="CVE"/>
        <reference ref_id="CVE-2010-4448" ref_url="http://linux.oracle.com/cve/CVE-2010-4448.html" source="CVE"/>
        <reference ref_id="CVE-2010-4450" ref_url="http://linux.oracle.com/cve/CVE-2010-4450.html" source="CVE"/>
        <reference ref_id="CVE-2010-4454" ref_url="http://linux.oracle.com/cve/CVE-2010-4454.html" source="CVE"/>
        <reference ref_id="CVE-2010-4462" ref_url="http://linux.oracle.com/cve/CVE-2010-4462.html" source="CVE"/>
        <reference ref_id="CVE-2010-4465" ref_url="http://linux.oracle.com/cve/CVE-2010-4465.html" source="CVE"/>
        <reference ref_id="CVE-2010-4466" ref_url="http://linux.oracle.com/cve/CVE-2010-4466.html" source="CVE"/>
        <reference ref_id="CVE-2010-4468" ref_url="http://linux.oracle.com/cve/CVE-2010-4468.html" source="CVE"/>
        <reference ref_id="CVE-2010-4471" ref_url="http://linux.oracle.com/cve/CVE-2010-4471.html" source="CVE"/>
        <reference ref_id="CVE-2010-4473" ref_url="http://linux.oracle.com/cve/CVE-2010-4473.html" source="CVE"/>
        <reference ref_id="CVE-2010-4475" ref_url="http://linux.oracle.com/cve/CVE-2010-4475.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:19.560-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:30.766-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:18.413-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23570 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.641-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:49.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108411"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108092"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108467"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108683"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108570"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108514"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108687"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108723"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108305"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108720"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:107799"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108728"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108627"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108578"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108128"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23569" version="21" class="patch">
      <metadata>
        <title>ELSA-2012:1426: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1426-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1426.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1568" ref_url="http://linux.oracle.com/cve/CVE-2012-1568.html" source="CVE"/>
        <reference ref_id="CVE-2012-2133" ref_url="http://linux.oracle.com/cve/CVE-2012-2133.html" source="CVE"/>
        <reference ref_id="CVE-2012-3400" ref_url="http://linux.oracle.com/cve/CVE-2012-3400.html" source="CVE"/>
        <reference ref_id="CVE-2012-3511" ref_url="http://linux.oracle.com/cve/CVE-2012-3511.html" source="CVE"/>
        <description>Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:02.306-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:30.545-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:18.176-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23569 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.200-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:49.078-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:111260"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:110787"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:110873"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:110425"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:111085"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:111096"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:110832"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:111266"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:111124"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:110843"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:110977"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:111110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23568" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1084: libsndfile security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libsndfile</product>
        </affected>
        <reference ref_id="ELSA-2011:1084-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1084.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2696" ref_url="http://linux.oracle.com/cve/CVE-2011-2696.html" source="CVE"/>
        <description>Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:16.404-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:30.451-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:18.066-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23568 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:56.080-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:48.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libsndfile is earlier than 0:1.0.20-3.el6_1.1" test_ref="oval:org.mitre.oval:tst:108954"/>
          <criterion comment="libsndfile-devel is earlier than 0:1.0.20-3.el6_1.1" test_ref="oval:org.mitre.oval:tst:109101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23567" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0509: rdma security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ibacm</product>
          <product>infinipath-psm</product>
          <product>libibmad</product>
          <product>libibumad</product>
          <product>libibverbs</product>
          <product>libmlx4</product>
          <product>librdmacm</product>
          <product>opensm</product>
          <product>rdma</product>
          <product>ibsim</product>
          <product>ibutils</product>
          <product>infiniband-diags</product>
        </affected>
        <reference ref_id="ELSA-2013:0509-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0509.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4517" ref_url="http://linux.oracle.com/cve/CVE-2012-4517.html" source="CVE"/>
        <reference ref_id="CVE-2012-4518" ref_url="http://linux.oracle.com/cve/CVE-2012-4518.html" source="CVE"/>
        <description>ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:35.995-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:30.242-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:17.840-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23567 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.140-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:48.691-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="infinipath-psm-devel is earlier than 0:3.0.1-115.1015_open.1.el6" test_ref="oval:org.mitre.oval:tst:111448"/>
          <criterion comment="infinipath-psm is earlier than 0:3.0.1-115.1015_open.1.el6" test_ref="oval:org.mitre.oval:tst:111456"/>
          <criterion comment="rdma is earlier than 0:3.6-1.el6" test_ref="oval:org.mitre.oval:tst:110625"/>
          <criterion comment="libibverbs-devel is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:111276"/>
          <criterion comment="libibverbs is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:111065"/>
          <criterion comment="libibverbs-devel-static is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:111444"/>
          <criterion comment="libibverbs-utils is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:111309"/>
          <criterion comment="libmlx4-static is earlier than 0:1.0.4-1.el6" test_ref="oval:org.mitre.oval:tst:111023"/>
          <criterion comment="libmlx4 is earlier than 0:1.0.4-1.el6" test_ref="oval:org.mitre.oval:tst:111473"/>
          <criterion comment="libibumad is earlier than 0:1.3.8-1.el6" test_ref="oval:org.mitre.oval:tst:111581"/>
          <criterion comment="libibumad-devel is earlier than 0:1.3.8-1.el6" test_ref="oval:org.mitre.oval:tst:111127"/>
          <criterion comment="libibumad-static is earlier than 0:1.3.8-1.el6" test_ref="oval:org.mitre.oval:tst:111379"/>
          <criterion comment="libibmad-static is earlier than 0:1.3.9-1.el6" test_ref="oval:org.mitre.oval:tst:111104"/>
          <criterion comment="libibmad is earlier than 0:1.3.9-1.el6" test_ref="oval:org.mitre.oval:tst:111521"/>
          <criterion comment="libibmad-devel is earlier than 0:1.3.9-1.el6" test_ref="oval:org.mitre.oval:tst:111447"/>
          <criterion comment="opensm-static is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:110635"/>
          <criterion comment="opensm is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:111563"/>
          <criterion comment="opensm-devel is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:111418"/>
          <criterion comment="opensm-libs is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:111600"/>
          <criterion comment="ibutils is earlier than 0:1.5.7-7.el6" test_ref="oval:org.mitre.oval:tst:111579"/>
          <criterion comment="ibutils-libs is earlier than 0:1.5.7-7.el6" test_ref="oval:org.mitre.oval:tst:111613"/>
          <criterion comment="ibutils-devel is earlier than 0:1.5.7-7.el6" test_ref="oval:org.mitre.oval:tst:111631"/>
          <criterion comment="ibsim is earlier than 0:0.5-7.el6" test_ref="oval:org.mitre.oval:tst:111629"/>
          <criterion comment="ibacm is earlier than 0:1.0.8-0.git7a3adb7.el6" test_ref="oval:org.mitre.oval:tst:111072"/>
          <criterion comment="ibacm-devel is earlier than 0:1.0.8-0.git7a3adb7.el6" test_ref="oval:org.mitre.oval:tst:111518"/>
          <criterion comment="infiniband-diags-devel-static is earlier than 0:1.5.12-5.el6" test_ref="oval:org.mitre.oval:tst:111573"/>
          <criterion comment="infiniband-diags is earlier than 0:1.5.12-5.el6" test_ref="oval:org.mitre.oval:tst:111543"/>
          <criterion comment="infiniband-diags-devel is earlier than 0:1.5.12-5.el6" test_ref="oval:org.mitre.oval:tst:111526"/>
          <criterion comment="librdmacm-utils is earlier than 0:1.0.17-0.git4b5c1aa.el6" test_ref="oval:org.mitre.oval:tst:111499"/>
          <criterion comment="librdmacm is earlier than 0:1.0.17-0.git4b5c1aa.el6" test_ref="oval:org.mitre.oval:tst:111541"/>
          <criterion comment="librdmacm-static is earlier than 0:1.0.17-0.git4b5c1aa.el6" test_ref="oval:org.mitre.oval:tst:111179"/>
          <criterion comment="librdmacm-devel is earlier than 0:1.0.17-0.git4b5c1aa.el6" test_ref="oval:org.mitre.oval:tst:110671"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23566" version="5" class="patch">
      <metadata>
        <title>ELSA-2013:1402: Adobe Reader - notification of end of updates (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2013:1402-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1402.html" source="VENDOR"/>
        <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF). Adobe Reader 9 reached the end of its support cycle on June
26, 2013, and will not receive any more security updates. Future versions
of Adobe Acrobat Reader will not be available with Red Hat Enterprise
Linux.
The Adobe Reader packages in the Red Hat Network (RHN) channels will
continue to be available. Red Hat will continue to provide these packages
only as a courtesy to customers. Red Hat will not provide updates to the
Adobe Reader packages.
This update disables the Adobe Reader web browser plug-in, which is
available via the acroread-plugin package, to prevent the exploitation of
security issues without user interaction when a user visits a malicious web
page.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:08.783-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:30.194-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:17.766-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23566 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:59.084-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:48.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="acroread-plugin is earlier than 0:9.5.5-1.el6_4.1" test_ref="oval:org.mitre.oval:tst:112112"/>
          <criterion comment="acroread is earlier than 0:9.5.5-1.el6_4.1" test_ref="oval:org.mitre.oval:tst:112443"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23565" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0321: cvs security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>cvs</product>
        </affected>
        <reference ref_id="ELSA-2012:0321-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0321.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0804" ref_url="http://linux.oracle.com/cve/CVE-2012-0804.html" source="CVE"/>
        <description>Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:01.824-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:30.094-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:17.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23565 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.786-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:48.409-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cvs-inetd is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:109994"/>
            <criterion comment="cvs is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:109939"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="cvs is earlier than 0:1.11.23-11.el6_2.1" test_ref="oval:org.mitre.oval:tst:109935"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23564" version="38" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1268: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1268-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1268.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1718" ref_url="http://linux.oracle.com/cve/CVE-2013-1718.html" source="CVE"/>
        <reference ref_id="CVE-2013-1722" ref_url="http://linux.oracle.com/cve/CVE-2013-1722.html" source="CVE"/>
        <reference ref_id="CVE-2013-1725" ref_url="http://linux.oracle.com/cve/CVE-2013-1725.html" source="CVE"/>
        <reference ref_id="CVE-2013-1730" ref_url="http://linux.oracle.com/cve/CVE-2013-1730.html" source="CVE"/>
        <reference ref_id="CVE-2013-1732" ref_url="http://linux.oracle.com/cve/CVE-2013-1732.html" source="CVE"/>
        <reference ref_id="CVE-2013-1735" ref_url="http://linux.oracle.com/cve/CVE-2013-1735.html" source="CVE"/>
        <reference ref_id="CVE-2013-1736" ref_url="http://linux.oracle.com/cve/CVE-2013-1736.html" source="CVE"/>
        <reference ref_id="CVE-2013-1737" ref_url="http://linux.oracle.com/cve/CVE-2013-1737.html" source="CVE"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:34.159-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:29.740-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:17.311-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23564 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.898-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:48.099-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:51:34.102-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:51:34.102-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:107739"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:107344"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:107789"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:107744"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:107780"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:107563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23563" version="73" class="patch">
      <metadata>
        <title>ELSA-2010:0865: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2010:0865-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0865.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-3541" ref_url="http://linux.oracle.com/cve/CVE-2010-3541.html" source="CVE"/>
        <reference ref_id="CVE-2010-3548" ref_url="http://linux.oracle.com/cve/CVE-2010-3548.html" source="CVE"/>
        <reference ref_id="CVE-2010-3549" ref_url="http://linux.oracle.com/cve/CVE-2010-3549.html" source="CVE"/>
        <reference ref_id="CVE-2010-3551" ref_url="http://linux.oracle.com/cve/CVE-2010-3551.html" source="CVE"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3554" ref_url="http://linux.oracle.com/cve/CVE-2010-3554.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3561" ref_url="http://linux.oracle.com/cve/CVE-2010-3561.html" source="CVE"/>
        <reference ref_id="CVE-2010-3562" ref_url="http://linux.oracle.com/cve/CVE-2010-3562.html" source="CVE"/>
        <reference ref_id="CVE-2010-3564" ref_url="http://linux.oracle.com/cve/CVE-2010-3564.html" source="CVE"/>
        <reference ref_id="CVE-2010-3565" ref_url="http://linux.oracle.com/cve/CVE-2010-3565.html" source="CVE"/>
        <reference ref_id="CVE-2010-3567" ref_url="http://linux.oracle.com/cve/CVE-2010-3567.html" source="CVE"/>
        <reference ref_id="CVE-2010-3568" ref_url="http://linux.oracle.com/cve/CVE-2010-3568.html" source="CVE"/>
        <reference ref_id="CVE-2010-3569" ref_url="http://linux.oracle.com/cve/CVE-2010-3569.html" source="CVE"/>
        <reference ref_id="CVE-2010-3573" ref_url="http://linux.oracle.com/cve/CVE-2010-3573.html" source="CVE"/>
        <reference ref_id="CVE-2010-3574" ref_url="http://linux.oracle.com/cve/CVE-2010-3574.html" source="CVE"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:29.061-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:29.030-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:16.641-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23563 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:56.445-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:107430"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:108160"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:108134"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:108005"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:107540"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23561" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0185: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2014:0185-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0185.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-6466" ref_url="http://linux.oracle.com/cve/CVE-2013-6466.html" source="CVE"/>
        <description>Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:07.378-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.825-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:16.389-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23561 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.541-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.457-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:50:49.362-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:50:49.362-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:107444"/>
            <criterion comment="openswan is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:108072"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:107716"/>
            <criterion comment="openswan is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:107126"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23560" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:1002: mod_auth_mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>mod_auth_mysql</product>
        </affected>
        <reference ref_id="ELSA-2010:1002-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-1002.html" source="VENDOR"/>
        <reference ref_id="CVE-2008-2384" ref_url="http://linux.oracle.com/cve/CVE-2008-2384.html" source="CVE"/>
        <description>SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:35.758-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.726-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:16.280-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23560 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:55.433-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.353-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="mod_auth_mysql is earlier than 1:3.0.0-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:108300"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23559" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:0165: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0165-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0165.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3174" ref_url="http://linux.oracle.com/cve/CVE-2012-3174.html" source="CVE"/>
        <reference ref_id="CVE-2013-0422" ref_url="http://linux.oracle.com/cve/CVE-2013-0422.html" source="CVE"/>
        <description>Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114.  CVE-2013-0422 covers both the JMX/MBean and Reflection API issues.  NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks.  NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11.  If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:20.278-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.634-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:16.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23559 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:57.085-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:110518"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:110392"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:111244"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:111184"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:111001"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:111075"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:111138"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:111038"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:110983"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:110438"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23558" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1132: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dbus</product>
        </affected>
        <reference ref_id="ELSA-2011:1132-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1132.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2200" ref_url="http://linux.oracle.com/cve/CVE-2011-2200.html" source="CVE"/>
        <description>The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or conduct unspecified state-modification attacks via crafted messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:16.183-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.486-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:16.036-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23558 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:57.797-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.124-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-devel is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:109249"/>
            <criterion comment="dbus is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:109213"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:109036"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:108701"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-devel is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109115"/>
            <criterion comment="dbus is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109165"/>
            <criterion comment="dbus-x11 is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109316"/>
            <criterion comment="dbus-libs is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109283"/>
            <criterion comment="dbus-doc is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:109095"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23557" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1409: xinetd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference ref_id="ELSA-2013:1409-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1409.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4342" ref_url="http://linux.oracle.com/cve/CVE-2013-4342.html" source="CVE"/>
        <description>xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:38.227-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.387-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:15.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23557 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.306-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:47.005-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:50:11.441-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:50:11.441-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="xinetd is earlier than 2:2.3.14-39.el6_4" test_ref="oval:org.mitre.oval:tst:107429"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="xinetd is earlier than 2:2.3.14-20.el5_10" test_ref="oval:org.mitre.oval:tst:107637"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23556" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0889: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2010:0889-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0889.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3855" ref_url="http://linux.oracle.com/cve/CVE-2010-3855.html" source="CVE"/>
        <description>Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:33.725-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.277-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:15.805-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23556 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.409-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:46.897-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:108024"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:108104"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:108080"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:107896"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:108125"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:107962"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23555" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1274: hplip security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>hplip</product>
        </affected>
        <reference ref_id="ELSA-2013:1274-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1274.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4325" ref_url="http://linux.oracle.com/cve/CVE-2013-4325.html" source="CVE"/>
        <description>The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:50:58.947-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:28.178-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:15.692-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23555 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:56.570-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:46.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="hplip-common is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:112400"/>
          <criterion comment="hplip-libs is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:112257"/>
          <criterion comment="libsane-hpaio is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:112342"/>
          <criterion comment="hplip is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:112201"/>
          <criterion comment="hplip-gui is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:112360"/>
          <criterion comment="hpijs is earlier than 1:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:112422"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23554" version="106" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1014: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:1014-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1014.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1500" ref_url="http://linux.oracle.com/cve/CVE-2013-1500.html" source="CVE"/>
        <reference ref_id="CVE-2013-1571" ref_url="http://linux.oracle.com/cve/CVE-2013-1571.html" source="CVE"/>
        <reference ref_id="CVE-2013-2407" ref_url="http://linux.oracle.com/cve/CVE-2013-2407.html" source="CVE"/>
        <reference ref_id="CVE-2013-2412" ref_url="http://linux.oracle.com/cve/CVE-2013-2412.html" source="CVE"/>
        <reference ref_id="CVE-2013-2443" ref_url="http://linux.oracle.com/cve/CVE-2013-2443.html" source="CVE"/>
        <reference ref_id="CVE-2013-2444" ref_url="http://linux.oracle.com/cve/CVE-2013-2444.html" source="CVE"/>
        <reference ref_id="CVE-2013-2445" ref_url="http://linux.oracle.com/cve/CVE-2013-2445.html" source="CVE"/>
        <reference ref_id="CVE-2013-2446" ref_url="http://linux.oracle.com/cve/CVE-2013-2446.html" source="CVE"/>
        <reference ref_id="CVE-2013-2447" ref_url="http://linux.oracle.com/cve/CVE-2013-2447.html" source="CVE"/>
        <reference ref_id="CVE-2013-2448" ref_url="http://linux.oracle.com/cve/CVE-2013-2448.html" source="CVE"/>
        <reference ref_id="CVE-2013-2450" ref_url="http://linux.oracle.com/cve/CVE-2013-2450.html" source="CVE"/>
        <reference ref_id="CVE-2013-2452" ref_url="http://linux.oracle.com/cve/CVE-2013-2452.html" source="CVE"/>
        <reference ref_id="CVE-2013-2453" ref_url="http://linux.oracle.com/cve/CVE-2013-2453.html" source="CVE"/>
        <reference ref_id="CVE-2013-2455" ref_url="http://linux.oracle.com/cve/CVE-2013-2455.html" source="CVE"/>
        <reference ref_id="CVE-2013-2456" ref_url="http://linux.oracle.com/cve/CVE-2013-2456.html" source="CVE"/>
        <reference ref_id="CVE-2013-2457" ref_url="http://linux.oracle.com/cve/CVE-2013-2457.html" source="CVE"/>
        <reference ref_id="CVE-2013-2459" ref_url="http://linux.oracle.com/cve/CVE-2013-2459.html" source="CVE"/>
        <reference ref_id="CVE-2013-2461" ref_url="http://linux.oracle.com/cve/CVE-2013-2461.html" source="CVE"/>
        <reference ref_id="CVE-2013-2463" ref_url="http://linux.oracle.com/cve/CVE-2013-2463.html" source="CVE"/>
        <reference ref_id="CVE-2013-2465" ref_url="http://linux.oracle.com/cve/CVE-2013-2465.html" source="CVE"/>
        <reference ref_id="CVE-2013-2469" ref_url="http://linux.oracle.com/cve/CVE-2013-2469.html" source="CVE"/>
        <reference ref_id="CVE-2013-2470" ref_url="http://linux.oracle.com/cve/CVE-2013-2470.html" source="CVE"/>
        <reference ref_id="CVE-2013-2471" ref_url="http://linux.oracle.com/cve/CVE-2013-2471.html" source="CVE"/>
        <reference ref_id="CVE-2013-2472" ref_url="http://linux.oracle.com/cve/CVE-2013-2472.html" source="CVE"/>
        <reference ref_id="CVE-2013-2473" ref_url="http://linux.oracle.com/cve/CVE-2013-2473.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.	NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:40.097-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:27.214-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:14.674-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23554 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.829-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:45.900-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:49:39.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:49:39.289-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107175"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107431"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107392"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107261"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:107379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:106701"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:107218"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:107161"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:107500"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:107040"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23553" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0705: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openoffice.org</product>
        </affected>
        <reference ref_id="ELSA-2012:0705-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0705.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1149" ref_url="http://linux.oracle.com/cve/CVE-2012-1149.html" source="CVE"/>
        <reference ref_id="CVE-2012-2334" ref_url="http://linux.oracle.com/cve/CVE-2012-2334.html" source="CVE"/>
        <description>Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt) document, which triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:26.711-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:26.541-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:13.976-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23553 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:54.867-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:45.306-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109967"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110070"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109837"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109597"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109862"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110134"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110362"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110140"/>
            <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110338"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110156"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110226"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110089"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110310"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110207"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110187"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110264"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110173"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110141"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110259"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110319"/>
            <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110058"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110315"/>
            <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109821"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109362"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110323"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110069"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110252"/>
            <criterion comment="openoffice.org is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110129"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110302"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110211"/>
            <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109885"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109823"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109961"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110325"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110256"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109984"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109814"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110026"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109833"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109751"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110029"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110300"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109365"/>
            <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110294"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110288"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110355"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110257"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109786"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109593"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110205"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110182"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109787"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110042"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110128"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109656"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110233"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110044"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109971"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110208"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110107"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110318"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110331"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109749"/>
            <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110073"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110176"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110115"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109995"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110352"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109864"/>
            <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110307"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110239"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110088"/>
            <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109440"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110077"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110322"/>
            <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109710"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:109887"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:110334"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110033"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110456"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109459"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110349"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110147"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110416"/>
            <criterion comment="autocorr-af is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109616"/>
            <criterion comment="openoffice.org-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110327"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110144"/>
            <criterion comment="openoffice.org-langpack-dz is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110414"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110269"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110036"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110380"/>
            <criterion comment="broffice.org-brand is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110332"/>
            <criterion comment="autocorr-vi is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109407"/>
            <criterion comment="openoffice.org-langpack-uk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110413"/>
            <criterion comment="autocorr-ja is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110305"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110340"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110460"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110125"/>
            <criterion comment="openoffice.org-calc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110087"/>
            <criterion comment="openoffice.org-opensymbol-fonts is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109728"/>
            <criterion comment="autocorr-eu is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110261"/>
            <criterion comment="openoffice.org is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109948"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110236"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109758"/>
            <criterion comment="openoffice.org-presentation-minimizer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109801"/>
            <criterion comment="autocorr-sl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110473"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110179"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110219"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110263"/>
            <criterion comment="openoffice.org-draw is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110316"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110003"/>
            <criterion comment="openoffice.org-devel is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109926"/>
            <criterion comment="autocorr-ga is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110367"/>
            <criterion comment="openoffice.org-report-builder is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110412"/>
            <criterion comment="openoffice.org-calc-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109734"/>
            <criterion comment="autocorr-mn is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110346"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110321"/>
            <criterion comment="broffice.org-math is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110253"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110152"/>
            <criterion comment="autocorr-pl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110356"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109936"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109956"/>
            <criterion comment="openoffice.org-base-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110137"/>
            <criterion comment="broffice.org-writer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110366"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110393"/>
            <criterion comment="openoffice.org-brand is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110371"/>
            <criterion comment="broffice.org-impress is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110227"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110353"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110250"/>
            <criterion comment="autocorr-da is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110204"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109788"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110202"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109911"/>
            <criterion comment="openoffice.org-langpack-pa is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110407"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109907"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109505"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109708"/>
            <criterion comment="openoffice.org-writer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110243"/>
            <criterion comment="broffice.org-calc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110457"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110337"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110490"/>
            <criterion comment="autocorr-tr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109988"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110299"/>
            <criterion comment="autocorr-sv is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109891"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110342"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110206"/>
            <criterion comment="autocorr-fr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110223"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109563"/>
            <criterion comment="autocorr-es is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110370"/>
            <criterion comment="openoffice.org-langpack-ro is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109419"/>
            <criterion comment="openoffice.org-langpack-en is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110417"/>
            <criterion comment="autocorr-fi is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110374"/>
            <criterion comment="openoffice.org-impress is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110385"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110232"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110271"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109408"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110471"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109889"/>
            <criterion comment="openoffice.org-langpack-mai_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110276"/>
            <criterion comment="openoffice.org-wiki-publisher is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110439"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110265"/>
            <criterion comment="autocorr-de is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110369"/>
            <criterion comment="broffice.org-base is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109871"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109491"/>
            <criterion comment="openoffice.org-math is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109529"/>
            <criterion comment="autocorr-nl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109753"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110354"/>
            <criterion comment="openoffice.org-draw-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110475"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109476"/>
            <criterion comment="autocorr-bg is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110320"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109829"/>
            <criterion comment="openoffice.org-bsh is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110397"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110284"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110192"/>
            <criterion comment="openoffice.org-langpack-sr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110410"/>
            <criterion comment="openoffice.org-math-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109854"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110185"/>
            <criterion comment="autocorr-ru is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110005"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110444"/>
            <criterion comment="autocorr-en is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110377"/>
            <criterion comment="autocorr-sk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109912"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110286"/>
            <criterion comment="autocorr-lt is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110343"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110390"/>
            <criterion comment="autocorr-cs is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110290"/>
            <criterion comment="autocorr-pt is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110053"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110363"/>
            <criterion comment="openoffice.org-writer-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110409"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109646"/>
            <criterion comment="openoffice.org-rhino is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110330"/>
            <criterion comment="openoffice.org-presenter-screen is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110027"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110297"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110433"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109853"/>
            <criterion comment="openoffice.org-impress-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110449"/>
            <criterion comment="broffice.org-draw is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110251"/>
            <criterion comment="openoffice.org-pdfimport is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110279"/>
            <criterion comment="autocorr-fa is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110447"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110293"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109909"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110194"/>
            <criterion comment="autocorr-zh is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110396"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110268"/>
            <criterion comment="autocorr-ko is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110406"/>
            <criterion comment="openoffice.org-headless is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110445"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109943"/>
            <criterion comment="autocorr-it is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110295"/>
            <criterion comment="openoffice.org-ogltrans is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110421"/>
            <criterion comment="openoffice.org-base is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110381"/>
            <criterion comment="autocorr-hu is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110228"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109951"/>
            <criterion comment="openoffice.org-ure is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:109746"/>
            <criterion comment="autocorr-lb is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110436"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:110278"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23552" version="169" class="patch">
      <metadata>
        <title>ELSA-2013:0626: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2013:0626-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0626.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1541" ref_url="http://linux.oracle.com/cve/CVE-2012-1541.html" source="CVE"/>
        <reference ref_id="CVE-2012-3174" ref_url="http://linux.oracle.com/cve/CVE-2012-3174.html" source="CVE"/>
        <reference ref_id="CVE-2012-3213" ref_url="http://linux.oracle.com/cve/CVE-2012-3213.html" source="CVE"/>
        <reference ref_id="CVE-2012-3342" ref_url="http://linux.oracle.com/cve/CVE-2012-3342.html" source="CVE"/>
        <reference ref_id="CVE-2012-5085" ref_url="http://linux.oracle.com/cve/CVE-2012-5085.html" source="CVE"/>
        <reference ref_id="CVE-2013-0351" ref_url="http://linux.oracle.com/cve/CVE-2013-0351.html" source="CVE"/>
        <reference ref_id="CVE-2013-0409" ref_url="http://linux.oracle.com/cve/CVE-2013-0409.html" source="CVE"/>
        <reference ref_id="CVE-2013-0419" ref_url="http://linux.oracle.com/cve/CVE-2013-0419.html" source="CVE"/>
        <reference ref_id="CVE-2013-0422" ref_url="http://linux.oracle.com/cve/CVE-2013-0422.html" source="CVE"/>
        <reference ref_id="CVE-2013-0423" ref_url="http://linux.oracle.com/cve/CVE-2013-0423.html" source="CVE"/>
        <reference ref_id="CVE-2013-0424" ref_url="http://linux.oracle.com/cve/CVE-2013-0424.html" source="CVE"/>
        <reference ref_id="CVE-2013-0425" ref_url="http://linux.oracle.com/cve/CVE-2013-0425.html" source="CVE"/>
        <reference ref_id="CVE-2013-0426" ref_url="http://linux.oracle.com/cve/CVE-2013-0426.html" source="CVE"/>
        <reference ref_id="CVE-2013-0427" ref_url="http://linux.oracle.com/cve/CVE-2013-0427.html" source="CVE"/>
        <reference ref_id="CVE-2013-0428" ref_url="http://linux.oracle.com/cve/CVE-2013-0428.html" source="CVE"/>
        <reference ref_id="CVE-2013-0431" ref_url="http://linux.oracle.com/cve/CVE-2013-0431.html" source="CVE"/>
        <reference ref_id="CVE-2013-0432" ref_url="http://linux.oracle.com/cve/CVE-2013-0432.html" source="CVE"/>
        <reference ref_id="CVE-2013-0433" ref_url="http://linux.oracle.com/cve/CVE-2013-0433.html" source="CVE"/>
        <reference ref_id="CVE-2013-0434" ref_url="http://linux.oracle.com/cve/CVE-2013-0434.html" source="CVE"/>
        <reference ref_id="CVE-2013-0435" ref_url="http://linux.oracle.com/cve/CVE-2013-0435.html" source="CVE"/>
        <reference ref_id="CVE-2013-0437" ref_url="http://linux.oracle.com/cve/CVE-2013-0437.html" source="CVE"/>
        <reference ref_id="CVE-2013-0438" ref_url="http://linux.oracle.com/cve/CVE-2013-0438.html" source="CVE"/>
        <reference ref_id="CVE-2013-0440" ref_url="http://linux.oracle.com/cve/CVE-2013-0440.html" source="CVE"/>
        <reference ref_id="CVE-2013-0441" ref_url="http://linux.oracle.com/cve/CVE-2013-0441.html" source="CVE"/>
        <reference ref_id="CVE-2013-0442" ref_url="http://linux.oracle.com/cve/CVE-2013-0442.html" source="CVE"/>
        <reference ref_id="CVE-2013-0443" ref_url="http://linux.oracle.com/cve/CVE-2013-0443.html" source="CVE"/>
        <reference ref_id="CVE-2013-0444" ref_url="http://linux.oracle.com/cve/CVE-2013-0444.html" source="CVE"/>
        <reference ref_id="CVE-2013-0445" ref_url="http://linux.oracle.com/cve/CVE-2013-0445.html" source="CVE"/>
        <reference ref_id="CVE-2013-0446" ref_url="http://linux.oracle.com/cve/CVE-2013-0446.html" source="CVE"/>
        <reference ref_id="CVE-2013-0449" ref_url="http://linux.oracle.com/cve/CVE-2013-0449.html" source="CVE"/>
        <reference ref_id="CVE-2013-0450" ref_url="http://linux.oracle.com/cve/CVE-2013-0450.html" source="CVE"/>
        <reference ref_id="CVE-2013-0809" ref_url="http://linux.oracle.com/cve/CVE-2013-0809.html" source="CVE"/>
        <reference ref_id="CVE-2013-1473" ref_url="http://linux.oracle.com/cve/CVE-2013-1473.html" source="CVE"/>
        <reference ref_id="CVE-2013-1476" ref_url="http://linux.oracle.com/cve/CVE-2013-1476.html" source="CVE"/>
        <reference ref_id="CVE-2013-1478" ref_url="http://linux.oracle.com/cve/CVE-2013-1478.html" source="CVE"/>
        <reference ref_id="CVE-2013-1480" ref_url="http://linux.oracle.com/cve/CVE-2013-1480.html" source="CVE"/>
        <reference ref_id="CVE-2013-1484" ref_url="http://linux.oracle.com/cve/CVE-2013-1484.html" source="CVE"/>
        <reference ref_id="CVE-2013-1485" ref_url="http://linux.oracle.com/cve/CVE-2013-1485.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <reference ref_id="CVE-2013-1487" ref_url="http://linux.oracle.com/cve/CVE-2013-1487.html" source="CVE"/>
        <reference ref_id="CVE-2013-1493" ref_url="http://linux.oracle.com/cve/CVE-2013-1493.html" source="CVE"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:40.693-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:25.135-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:12.285-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23552 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.014-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:44.034-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111804"/>
          <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111728"/>
          <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111818"/>
          <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111750"/>
          <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111271"/>
          <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:111843"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23551" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0407: logrotate security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>logrotate</product>
        </affected>
        <reference ref_id="ELSA-2011:0407-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0407.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1098" ref_url="http://linux.oracle.com/cve/CVE-2011-1098.html" source="CVE"/>
        <reference ref_id="CVE-2011-1154" ref_url="http://linux.oracle.com/cve/CVE-2011-1154.html" source="CVE"/>
        <reference ref_id="CVE-2011-1155" ref_url="http://linux.oracle.com/cve/CVE-2011-1155.html" source="CVE"/>
        <description>The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:34.756-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:24.978-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:12.105-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23551 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.610-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:43.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="logrotate is earlier than 0:3.7.8-12.el6_0.1" test_ref="oval:org.mitre.oval:tst:108250"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23550" version="129" class="patch">
      <metadata>
        <title>ELSA-2011:0007: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0007-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0007.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2492" ref_url="http://linux.oracle.com/cve/CVE-2010-2492.html" source="CVE"/>
        <reference ref_id="CVE-2010-3067" ref_url="http://linux.oracle.com/cve/CVE-2010-3067.html" source="CVE"/>
        <reference ref_id="CVE-2010-3078" ref_url="http://linux.oracle.com/cve/CVE-2010-3078.html" source="CVE"/>
        <reference ref_id="CVE-2010-3080" ref_url="http://linux.oracle.com/cve/CVE-2010-3080.html" source="CVE"/>
        <reference ref_id="CVE-2010-3298" ref_url="http://linux.oracle.com/cve/CVE-2010-3298.html" source="CVE"/>
        <reference ref_id="CVE-2010-3477" ref_url="http://linux.oracle.com/cve/CVE-2010-3477.html" source="CVE"/>
        <reference ref_id="CVE-2010-3861" ref_url="http://linux.oracle.com/cve/CVE-2010-3861.html" source="CVE"/>
        <reference ref_id="CVE-2010-3865" ref_url="http://linux.oracle.com/cve/CVE-2010-3865.html" source="CVE"/>
        <reference ref_id="CVE-2010-3874" ref_url="http://linux.oracle.com/cve/CVE-2010-3874.html" source="CVE"/>
        <reference ref_id="CVE-2010-3876" ref_url="http://linux.oracle.com/cve/CVE-2010-3876.html" source="CVE"/>
        <reference ref_id="CVE-2010-3880" ref_url="http://linux.oracle.com/cve/CVE-2010-3880.html" source="CVE"/>
        <reference ref_id="CVE-2010-4072" ref_url="http://linux.oracle.com/cve/CVE-2010-4072.html" source="CVE"/>
        <reference ref_id="CVE-2010-4073" ref_url="http://linux.oracle.com/cve/CVE-2010-4073.html" source="CVE"/>
        <reference ref_id="CVE-2010-4074" ref_url="http://linux.oracle.com/cve/CVE-2010-4074.html" source="CVE"/>
        <reference ref_id="CVE-2010-4075" ref_url="http://linux.oracle.com/cve/CVE-2010-4075.html" source="CVE"/>
        <reference ref_id="CVE-2010-4077" ref_url="http://linux.oracle.com/cve/CVE-2010-4077.html" source="CVE"/>
        <reference ref_id="CVE-2010-4079" ref_url="http://linux.oracle.com/cve/CVE-2010-4079.html" source="CVE"/>
        <reference ref_id="CVE-2010-4080" ref_url="http://linux.oracle.com/cve/CVE-2010-4080.html" source="CVE"/>
        <reference ref_id="CVE-2010-4081" ref_url="http://linux.oracle.com/cve/CVE-2010-4081.html" source="CVE"/>
        <reference ref_id="CVE-2010-4082" ref_url="http://linux.oracle.com/cve/CVE-2010-4082.html" source="CVE"/>
        <reference ref_id="CVE-2010-4083" ref_url="http://linux.oracle.com/cve/CVE-2010-4083.html" source="CVE"/>
        <reference ref_id="CVE-2010-4158" ref_url="http://linux.oracle.com/cve/CVE-2010-4158.html" source="CVE"/>
        <reference ref_id="CVE-2010-4160" ref_url="http://linux.oracle.com/cve/CVE-2010-4160.html" source="CVE"/>
        <reference ref_id="CVE-2010-4162" ref_url="http://linux.oracle.com/cve/CVE-2010-4162.html" source="CVE"/>
        <reference ref_id="CVE-2010-4163" ref_url="http://linux.oracle.com/cve/CVE-2010-4163.html" source="CVE"/>
        <reference ref_id="CVE-2010-4242" ref_url="http://linux.oracle.com/cve/CVE-2010-4242.html" source="CVE"/>
        <reference ref_id="CVE-2010-4248" ref_url="http://linux.oracle.com/cve/CVE-2010-4248.html" source="CVE"/>
        <reference ref_id="CVE-2010-4249" ref_url="http://linux.oracle.com/cve/CVE-2010-4249.html" source="CVE"/>
        <reference ref_id="CVE-2010-4263" ref_url="http://linux.oracle.com/cve/CVE-2010-4263.html" source="CVE"/>
        <reference ref_id="CVE-2010-4525" ref_url="http://linux.oracle.com/cve/CVE-2010-4525.html" source="CVE"/>
        <reference ref_id="CVE-2010-4668" ref_url="http://linux.oracle.com/cve/CVE-2010-4668.html" source="CVE"/>
        <description>The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.37-rc7 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device, related to an unaligned map.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4163.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:23.251-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:23.822-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:10.811-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23550 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:57.560-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:42.948-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:108214"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:108182"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:108008"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:107578"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:108071"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:107663"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:108295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:108294"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:107979"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:107347"/>
          <criterion comment="kernel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:108015"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23549" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0918: cvs security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cvs</product>
        </affected>
        <reference ref_id="ELSA-2010:0918-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0918.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3846" ref_url="http://linux.oracle.com/cve/CVE-2010-3846.html" source="CVE"/>
        <description>Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:31.989-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:23.734-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:10.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23549 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.872-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:42.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="cvs is earlier than 0:1.11.23-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:108231"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23547" version="42" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1823: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1823-04" ref_url="http://linux.oracle.com/errata/ELSA-2013-1823.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0772" ref_url="http://linux.oracle.com/cve/CVE-2013-0772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5609" ref_url="http://linux.oracle.com/cve/CVE-2013-5609.html" source="CVE"/>
        <reference ref_id="CVE-2013-5612" ref_url="http://linux.oracle.com/cve/CVE-2013-5612.html" source="CVE"/>
        <reference ref_id="CVE-2013-5613" ref_url="http://linux.oracle.com/cve/CVE-2013-5613.html" source="CVE"/>
        <reference ref_id="CVE-2013-5614" ref_url="http://linux.oracle.com/cve/CVE-2013-5614.html" source="CVE"/>
        <reference ref_id="CVE-2013-5616" ref_url="http://linux.oracle.com/cve/CVE-2013-5616.html" source="CVE"/>
        <reference ref_id="CVE-2013-5618" ref_url="http://linux.oracle.com/cve/CVE-2013-5618.html" source="CVE"/>
        <reference ref_id="CVE-2013-6671" ref_url="http://linux.oracle.com/cve/CVE-2013-6671.html" source="CVE"/>
        <reference ref_id="CVE-2013-6674" ref_url="http://linux.oracle.com/cve/CVE-2013-6674.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:12.841-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:23.332-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:10.302-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23547 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.762-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:42.493-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:48:43.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:48:43.008-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:112789"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:112383"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23546" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0859: poppler security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>poppler</product>
        </affected>
        <reference ref_id="ELSA-2010:0859-03" ref_url="http://linux.oracle.com/errata/ELSA-2010-0859.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3702" ref_url="http://linux.oracle.com/cve/CVE-2010-3702.html" source="CVE"/>
        <reference ref_id="CVE-2010-3703" ref_url="http://linux.oracle.com/cve/CVE-2010-3703.html" source="CVE"/>
        <reference ref_id="CVE-2010-3704" ref_url="http://linux.oracle.com/cve/CVE-2010-3704.html" source="CVE"/>
        <description>The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:31.018-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:23.145-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:10.101-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23546 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.966-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:42.326-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="poppler-qt4 is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107393"/>
          <criterion comment="poppler-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108105"/>
          <criterion comment="poppler-qt-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107884"/>
          <criterion comment="poppler-glib-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108102"/>
          <criterion comment="poppler-qt4-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107767"/>
          <criterion comment="poppler-qt is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107150"/>
          <criterion comment="poppler-glib is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108052"/>
          <criterion comment="poppler-utils is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107920"/>
          <criterion comment="poppler is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23544" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0320: libcgroup security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libcgroup</product>
        </affected>
        <reference ref_id="ELSA-2011:0320-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0320.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1006" ref_url="http://linux.oracle.com/cve/CVE-2011-1006.html" source="CVE"/>
        <reference ref_id="CVE-2011-1022" ref_url="http://linux.oracle.com/cve/CVE-2011-1022.html" source="CVE"/>
        <description>The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:18.736-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:22.932-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:09.852-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23544 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:56.175-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:42.184-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libcgroup-devel is earlier than 0:0.36.1-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108653"/>
          <criterion comment="libcgroup is earlier than 0:0.36.1-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108509"/>
          <criterion comment="libcgroup-pam is earlier than 0:0.36.1-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108397"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23543" version="57" class="patch">
      <metadata>
        <title>ELSA-2011:0206: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:0206-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0206.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0558" ref_url="http://linux.oracle.com/cve/CVE-2011-0558.html" source="CVE"/>
        <reference ref_id="CVE-2011-0559" ref_url="http://linux.oracle.com/cve/CVE-2011-0559.html" source="CVE"/>
        <reference ref_id="CVE-2011-0560" ref_url="http://linux.oracle.com/cve/CVE-2011-0560.html" source="CVE"/>
        <reference ref_id="CVE-2011-0561" ref_url="http://linux.oracle.com/cve/CVE-2011-0561.html" source="CVE"/>
        <reference ref_id="CVE-2011-0571" ref_url="http://linux.oracle.com/cve/CVE-2011-0571.html" source="CVE"/>
        <reference ref_id="CVE-2011-0572" ref_url="http://linux.oracle.com/cve/CVE-2011-0572.html" source="CVE"/>
        <reference ref_id="CVE-2011-0573" ref_url="http://linux.oracle.com/cve/CVE-2011-0573.html" source="CVE"/>
        <reference ref_id="CVE-2011-0574" ref_url="http://linux.oracle.com/cve/CVE-2011-0574.html" source="CVE"/>
        <reference ref_id="CVE-2011-0575" ref_url="http://linux.oracle.com/cve/CVE-2011-0575.html" source="CVE"/>
        <reference ref_id="CVE-2011-0577" ref_url="http://linux.oracle.com/cve/CVE-2011-0577.html" source="CVE"/>
        <reference ref_id="CVE-2011-0578" ref_url="http://linux.oracle.com/cve/CVE-2011-0578.html" source="CVE"/>
        <reference ref_id="CVE-2011-0607" ref_url="http://linux.oracle.com/cve/CVE-2011-0607.html" source="CVE"/>
        <reference ref_id="CVE-2011-0608" ref_url="http://linux.oracle.com/cve/CVE-2011-0608.html" source="CVE"/>
        <description>Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, and CVE-2011-0607.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:29.219-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:22.405-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:09.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23543 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.512-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:41.741-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:10.2.152.27-1.el6" test_ref="oval:org.mitre.oval:tst:108528"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23542" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0479: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2011:0479-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0479.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1486" ref_url="http://linux.oracle.com/cve/CVE-2011-1486.html" source="CVE"/>
        <description>libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:27.375-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:22.299-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:09.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23542 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:56.710-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:41.618-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.8.1-27.el6_0.6" test_ref="oval:org.mitre.oval:tst:108190"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.1-27.el6_0.6" test_ref="oval:org.mitre.oval:tst:108849"/>
          <criterion comment="libvirt-client is earlier than 0:0.8.1-27.el6_0.6" test_ref="oval:org.mitre.oval:tst:108485"/>
          <criterion comment="libvirt is earlier than 0:0.8.1-27.el6_0.6" test_ref="oval:org.mitre.oval:tst:108560"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23541" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1349: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>rpm</product>
        </affected>
        <reference ref_id="ELSA-2011:1349-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1349.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3378" ref_url="http://linux.oracle.com/cve/CVE-2011-3378.html" source="CVE"/>
        <description>RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:08.274-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:22.174-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:09.044-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23541 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.398-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:41.493-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109387"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109076"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:108450"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:108779"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109181"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109374"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:109052"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109338"/>
            <criterion comment="rpm is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109192"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109380"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:108424"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109234"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109366"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:109263"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23540" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0872: glibc security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2010:0872-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0872.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3847" ref_url="http://linux.oracle.com/cve/CVE-2010-3847.html" source="CVE"/>
        <reference ref_id="CVE-2010-3856" ref_url="http://linux.oracle.com/cve/CVE-2010-3856.html" source="CVE"/>
        <description>ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:32.198-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:22.038-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:08.883-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23540 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:58.969-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:41.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="glibc-devel is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:108192"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:108203"/>
          <criterion comment="glibc is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:108211"/>
          <criterion comment="nscd is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:108138"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:107745"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:108172"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:108222"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23539" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0197: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2011:0197-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0197.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4015" ref_url="http://linux.oracle.com/cve/CVE-2010-4015.html" source="CVE"/>
        <description>Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:36.088-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:21.915-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:08.764-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23539 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:52.651-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:41.223-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postgresql is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108430"/>
          <criterion comment="postgresql-server is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108575"/>
          <criterion comment="postgresql-libs is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108393"/>
          <criterion comment="postgresql-devel is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108539"/>
          <criterion comment="postgresql-pltcl is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108584"/>
          <criterion comment="postgresql-plpython is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108249"/>
          <criterion comment="postgresql-docs is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108293"/>
          <criterion comment="postgresql-plperl is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108272"/>
          <criterion comment="postgresql-test is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108361"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108568"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23538" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0018: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:0018-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0018.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3905" ref_url="http://linux.oracle.com/cve/CVE-2011-3905.html" source="CVE"/>
        <reference ref_id="CVE-2011-3919" ref_url="http://linux.oracle.com/cve/CVE-2011-3919.html" source="CVE"/>
        <description>Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:15.854-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:21.811-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:08.618-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23538 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:55.805-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:41.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:109127"/>
          <criterion comment="libxml2-python is earlier than 0:2.7.6-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:109629"/>
          <criterion comment="libxml2 is earlier than 0:2.7.6-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:109772"/>
          <criterion comment="libxml2-static is earlier than 0:2.7.6-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:109373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23537" version="33" class="patch">
      <metadata>
        <title>ELSA-2011:1478: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:1478-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1478.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3545" ref_url="http://linux.oracle.com/cve/CVE-2011-3545.html" source="CVE"/>
        <reference ref_id="CVE-2011-3547" ref_url="http://linux.oracle.com/cve/CVE-2011-3547.html" source="CVE"/>
        <reference ref_id="CVE-2011-3548" ref_url="http://linux.oracle.com/cve/CVE-2011-3548.html" source="CVE"/>
        <reference ref_id="CVE-2011-3549" ref_url="http://linux.oracle.com/cve/CVE-2011-3549.html" source="CVE"/>
        <reference ref_id="CVE-2011-3552" ref_url="http://linux.oracle.com/cve/CVE-2011-3552.html" source="CVE"/>
        <reference ref_id="CVE-2011-3554" ref_url="http://linux.oracle.com/cve/CVE-2011-3554.html" source="CVE"/>
        <reference ref_id="CVE-2011-3556" ref_url="http://linux.oracle.com/cve/CVE-2011-3556.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:53.172-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:21.469-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:08.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23537 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:54.358-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:40.754-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109536"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109615"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109507"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109038"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109504"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109704"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109718"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:109677"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109643"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:108876"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109503"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109681"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109603"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109017"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:109423"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23536" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0928: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0928-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0928.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1767" ref_url="http://linux.oracle.com/cve/CVE-2011-1767.html" source="CVE"/>
        <reference ref_id="CVE-2011-1768" ref_url="http://linux.oracle.com/cve/CVE-2011-1768.html" source="CVE"/>
        <reference ref_id="CVE-2011-2479" ref_url="http://linux.oracle.com/cve/CVE-2011-2479.html" source="CVE"/>
        <description>The Linux kernel before 2.6.39 does not properly create transparent huge pages in response to a MAP_PRIVATE mmap system call on /dev/zero, which allows local users to cause a denial of service (system crash) via a crafted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:15.620-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:21.281-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:08.087-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23536 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:53.304-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:40.537-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:108808"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:109092"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:108165"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:108962"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:108757"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:109039"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:108171"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:109086"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:108628"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:109109"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:108143"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23535" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0391: libvirt security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2011:0391-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0391.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1146" ref_url="http://linux.oracle.com/cve/CVE-2011-1146.html" source="CVE"/>
        <description>libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:35.787-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:21.186-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:07.981-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23535 - optimisation of Oracle Linux content" date="2014-05-05T17:34:00.748-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:35:57.205-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:40.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.8.1-27.el6_0.5" test_ref="oval:org.mitre.oval:tst:108536"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.1-27.el6_0.5" test_ref="oval:org.mitre.oval:tst:108145"/>
          <criterion comment="libvirt-client is earlier than 0:0.8.1-27.el6_0.5" test_ref="oval:org.mitre.oval:tst:108504"/>
          <criterion comment="libvirt is earlier than 0:0.8.1-27.el6_0.5" test_ref="oval:org.mitre.oval:tst:108538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23534" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0567: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:0567-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0567.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0871" ref_url="http://linux.oracle.com/cve/CVE-2013-0871.html" source="CVE"/>
        <description>Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:42.844-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:21.065-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:07.857-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23534 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:17.994-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:59.108-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:110918"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111443"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111482"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111519"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111680"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111593"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111711"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111539"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:110769"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111335"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111681"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:111745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23533" version="65" class="patch">
      <metadata>
        <title>ELSA-2010:0867: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2010:0867-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0867.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3636" ref_url="http://linux.oracle.com/cve/CVE-2010-3636.html" source="CVE"/>
        <reference ref_id="CVE-2010-3639" ref_url="http://linux.oracle.com/cve/CVE-2010-3639.html" source="CVE"/>
        <reference ref_id="CVE-2010-3640" ref_url="http://linux.oracle.com/cve/CVE-2010-3640.html" source="CVE"/>
        <reference ref_id="CVE-2010-3641" ref_url="http://linux.oracle.com/cve/CVE-2010-3641.html" source="CVE"/>
        <reference ref_id="CVE-2010-3642" ref_url="http://linux.oracle.com/cve/CVE-2010-3642.html" source="CVE"/>
        <reference ref_id="CVE-2010-3643" ref_url="http://linux.oracle.com/cve/CVE-2010-3643.html" source="CVE"/>
        <reference ref_id="CVE-2010-3644" ref_url="http://linux.oracle.com/cve/CVE-2010-3644.html" source="CVE"/>
        <reference ref_id="CVE-2010-3645" ref_url="http://linux.oracle.com/cve/CVE-2010-3645.html" source="CVE"/>
        <reference ref_id="CVE-2010-3646" ref_url="http://linux.oracle.com/cve/CVE-2010-3646.html" source="CVE"/>
        <reference ref_id="CVE-2010-3647" ref_url="http://linux.oracle.com/cve/CVE-2010-3647.html" source="CVE"/>
        <reference ref_id="CVE-2010-3648" ref_url="http://linux.oracle.com/cve/CVE-2010-3648.html" source="CVE"/>
        <reference ref_id="CVE-2010-3649" ref_url="http://linux.oracle.com/cve/CVE-2010-3649.html" source="CVE"/>
        <reference ref_id="CVE-2010-3650" ref_url="http://linux.oracle.com/cve/CVE-2010-3650.html" source="CVE"/>
        <reference ref_id="CVE-2010-3652" ref_url="http://linux.oracle.com/cve/CVE-2010-3652.html" source="CVE"/>
        <reference ref_id="CVE-2010-3654" ref_url="http://linux.oracle.com/cve/CVE-2010-3654.html" source="CVE"/>
        <description>Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:39.562-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:20.464-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:07.267-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23533 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.014-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:39.944-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:10.1.102.64-1.el6" test_ref="oval:org.mitre.oval:tst:108201"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23532" version="49" class="patch">
      <metadata>
        <title>ELSA-2010:0966: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2010:0966-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0966.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3766" ref_url="http://linux.oracle.com/cve/CVE-2010-3766.html" source="CVE"/>
        <reference ref_id="CVE-2010-3767" ref_url="http://linux.oracle.com/cve/CVE-2010-3767.html" source="CVE"/>
        <reference ref_id="CVE-2010-3768" ref_url="http://linux.oracle.com/cve/CVE-2010-3768.html" source="CVE"/>
        <reference ref_id="CVE-2010-3770" ref_url="http://linux.oracle.com/cve/CVE-2010-3770.html" source="CVE"/>
        <reference ref_id="CVE-2010-3771" ref_url="http://linux.oracle.com/cve/CVE-2010-3771.html" source="CVE"/>
        <reference ref_id="CVE-2010-3772" ref_url="http://linux.oracle.com/cve/CVE-2010-3772.html" source="CVE"/>
        <reference ref_id="CVE-2010-3773" ref_url="http://linux.oracle.com/cve/CVE-2010-3773.html" source="CVE"/>
        <reference ref_id="CVE-2010-3774" ref_url="http://linux.oracle.com/cve/CVE-2010-3774.html" source="CVE"/>
        <reference ref_id="CVE-2010-3775" ref_url="http://linux.oracle.com/cve/CVE-2010-3775.html" source="CVE"/>
        <reference ref_id="CVE-2010-3776" ref_url="http://linux.oracle.com/cve/CVE-2010-3776.html" source="CVE"/>
        <reference ref_id="CVE-2010-3777" ref_url="http://linux.oracle.com/cve/CVE-2010-3777.html" source="CVE"/>
        <description>Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:28.747-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:19.988-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:06.803-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23532 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.607-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:39.627-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:108195"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:108099"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el5" test_ref="oval:org.mitre.oval:tst:108302"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:107612"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:108056"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el6_0" test_ref="oval:org.mitre.oval:tst:108065"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23531" version="6" class="patch">
      <metadata>
        <title>ELSA-2014:0293: udisks security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>udisks</product>
        </affected>
        <reference ref_id="ELSA-2014:0293-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0293.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-0004" ref_url="http://linux.oracle.com/cve/CVE-2014-0004.html" source="CVE"/>
        <description>Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:24.959-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:05:06.693-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:07.711-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23531 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:29.748-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:58.940-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="udisks-devel-docs is earlier than 0:1.0.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:113712"/>
          <criterion comment="udisks-devel is earlier than 0:1.0.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:112790"/>
          <criterion comment="udisks is earlier than 0:1.0.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:113685"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23530" version="41" class="patch">
      <metadata>
        <title>ELSA-2011:1423: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2011:1423-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1423.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0708" ref_url="http://linux.oracle.com/cve/CVE-2011-0708.html" source="CVE"/>
        <reference ref_id="CVE-2011-1148" ref_url="http://linux.oracle.com/cve/CVE-2011-1148.html" source="CVE"/>
        <reference ref_id="CVE-2011-1466" ref_url="http://linux.oracle.com/cve/CVE-2011-1466.html" source="CVE"/>
        <reference ref_id="CVE-2011-1468" ref_url="http://linux.oracle.com/cve/CVE-2011-1468.html" source="CVE"/>
        <reference ref_id="CVE-2011-1469" ref_url="http://linux.oracle.com/cve/CVE-2011-1469.html" source="CVE"/>
        <reference ref_id="CVE-2011-1471" ref_url="http://linux.oracle.com/cve/CVE-2011-1471.html" source="CVE"/>
        <reference ref_id="CVE-2011-1938" ref_url="http://linux.oracle.com/cve/CVE-2011-1938.html" source="CVE"/>
        <reference ref_id="CVE-2011-2202" ref_url="http://linux.oracle.com/cve/CVE-2011-2202.html" source="CVE"/>
        <reference ref_id="CVE-2011-2483" ref_url="http://linux.oracle.com/cve/CVE-2011-2483.html" source="CVE"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:15.896-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:19.477-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:06.253-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23530 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:47.170-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:39.219-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109372"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109480"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109398"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109030"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109302"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109482"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109540"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109494"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:108569"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109148"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:108799"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:108572"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109443"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109484"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109513"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109451"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109425"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109226"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109023"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:108540"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:109229"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109420"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109530"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109381"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109483"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:108893"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:108983"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109510"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109390"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109049"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109490"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109091"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109322"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109472"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109167"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109344"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109315"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109238"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:108961"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109206"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109346"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109402"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109341"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109081"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109489"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109252"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:109176"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23529" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:1064: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2012:1064-02" ref_url="http://linux.oracle.com/errata/ELSA-2012-1064.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2744" ref_url="http://linux.oracle.com/cve/CVE-2012-2744.html" source="CVE"/>
        <reference ref_id="CVE-2012-2745" ref_url="http://linux.oracle.com/cve/CVE-2012-2745.html" source="CVE"/>
        <description>The copy_creds function in kernel/cred.c in the Linux kernel before 3.3.2 provides an invalid replacement session keyring to a child process, which allows local users to cause a denial of service (panic) via a crafted application that uses the fork system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:53.562-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:19.337-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:06.085-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23529 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:43.675-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:39.052-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110688"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110238"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110212"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110657"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110716"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110648"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110632"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110326"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:109914"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110570"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110593"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:110544"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23528" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1293: squid security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference ref_id="ELSA-2011:1293-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1293.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3205" ref_url="http://linux.oracle.com/cve/CVE-2011-3205.html" source="CVE"/>
        <description>Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response.  NOTE: This issue exists because of a CVE-2005-0094 regression.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:57.700-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:19.242-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:05.982-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23528 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:43.896-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:38.944-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="squid is earlier than 7:3.1.10-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:109291"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23527" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1480: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:1480-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1480.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5599" ref_url="http://linux.oracle.com/cve/CVE-2013-5599.html" source="CVE"/>
        <description>Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka presentation shell) implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors involving a CANVAS element, a mozTextStyle attribute, and an onresize event.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:33.304-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:19.143-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:05.880-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23527 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.593-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:38.839-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:48:12.777-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:48:12.777-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:107788"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:107374"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23526" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0406: quagga security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>quagga</product>
        </affected>
        <reference ref_id="ELSA-2011:0406-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0406.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1674" ref_url="http://linux.oracle.com/cve/CVE-2010-1674.html" source="CVE"/>
        <reference ref_id="CVE-2010-1675" ref_url="http://linux.oracle.com/cve/CVE-2010-1675.html" source="CVE"/>
        <description>bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path attribute.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:26.887-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:19.049-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:05.739-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23526 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.305-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:38.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="quagga-devel is earlier than 0:0.99.15-5.el6_0.2" test_ref="oval:org.mitre.oval:tst:108263"/>
          <criterion comment="quagga-contrib is earlier than 0:0.99.15-5.el6_0.2" test_ref="oval:org.mitre.oval:tst:108710"/>
          <criterion comment="quagga is earlier than 0:0.99.15-5.el6_0.2" test_ref="oval:org.mitre.oval:tst:108400"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23523" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0791: tomcat6 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference ref_id="ELSA-2011:0791-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0791.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3718" ref_url="http://linux.oracle.com/cve/CVE-2010-3718.html" source="CVE"/>
        <reference ref_id="CVE-2010-4172" ref_url="http://linux.oracle.com/cve/CVE-2010-4172.html" source="CVE"/>
        <reference ref_id="CVE-2011-0013" ref_url="http://linux.oracle.com/cve/CVE-2011-0013.html" source="CVE"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:33.255-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.794-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:05.258-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23523 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.104-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:38.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:108871"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:108459"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:108835"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:108589"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:108328"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:108809"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:109011"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:108885"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:108316"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23521" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0568: eclipse security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>eclipse</product>
          <product>eclipse-birt</product>
          <product>eclipse-callgraph</product>
          <product>eclipse-cdt</product>
          <product>eclipse-changelog</product>
          <product>eclipse-dtp</product>
          <product>eclipse-emf</product>
          <product>eclipse-gef</product>
          <product>eclipse-linuxprofilingframework</product>
          <product>eclipse-mylyn</product>
          <product>eclipse-oprofile</product>
          <product>eclipse-rse</product>
          <product>eclipse-valgrind</product>
          <product>icu4j</product>
          <product>jetty-eclipse</product>
          <product>objectweb-asm</product>
          <product>sat4j</product>
        </affected>
        <reference ref_id="ELSA-2011:0568-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0568.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4647" ref_url="http://linux.oracle.com/cve/CVE-2010-4647.html" source="CVE"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:39.080-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.550-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:04.852-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23521 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:41.492-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:37.907-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="jetty-eclipse is earlier than 0:6.1.24-2.el6" test_ref="oval:org.mitre.oval:tst:108789"/>
          <criterion comment="eclipse-rse is earlier than 0:3.2-1.el6" test_ref="oval:org.mitre.oval:tst:108930"/>
          <criterion comment="sat4j is earlier than 0:2.2.0-4.0.el6" test_ref="oval:org.mitre.oval:tst:108495"/>
          <criterion comment="objectweb-asm is earlier than 0:3.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:108903"/>
          <criterion comment="objectweb-asm-javadoc is earlier than 0:3.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:108801"/>
          <criterion comment="eclipse-emf-xsd-sdk is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:108966"/>
          <criterion comment="eclipse-emf is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:108919"/>
          <criterion comment="eclipse-emf-sdk is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:108739"/>
          <criterion comment="eclipse-emf-examples is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:108100"/>
          <criterion comment="eclipse-emf-xsd is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:108638"/>
          <criterion comment="eclipse-dtp is earlier than 0:1.8.1-1.1.el6" test_ref="oval:org.mitre.oval:tst:108955"/>
          <criterion comment="eclipse-birt is earlier than 0:2.6.0-1.1.el6" test_ref="oval:org.mitre.oval:tst:108675"/>
          <criterion comment="eclipse-linuxprofilingframework is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:108943"/>
          <criterion comment="eclipse-callgraph is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:108905"/>
          <criterion comment="eclipse-changelog is earlier than 1:2.7.0-1.el6" test_ref="oval:org.mitre.oval:tst:108636"/>
          <criterion comment="eclipse-valgrind is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:108427"/>
          <criterion comment="eclipse-oprofile is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:108888"/>
          <criterion comment="icu4j-javadoc is earlier than 1:4.2.1-5.el6" test_ref="oval:org.mitre.oval:tst:108233"/>
          <criterion comment="icu4j-eclipse is earlier than 1:4.2.1-5.el6" test_ref="oval:org.mitre.oval:tst:108907"/>
          <criterion comment="icu4j is earlier than 1:4.2.1-5.el6" test_ref="oval:org.mitre.oval:tst:108611"/>
          <criterion comment="eclipse-gef-sdk is earlier than 0:3.6.1-3.el6" test_ref="oval:org.mitre.oval:tst:108932"/>
          <criterion comment="eclipse-gef-examples is earlier than 0:3.6.1-3.el6" test_ref="oval:org.mitre.oval:tst:108554"/>
          <criterion comment="eclipse-gef is earlier than 0:3.6.1-3.el6" test_ref="oval:org.mitre.oval:tst:108764"/>
          <criterion comment="eclipse is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:108821"/>
          <criterion comment="eclipse-platform is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:108860"/>
          <criterion comment="eclipse-jdt is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:108665"/>
          <criterion comment="eclipse-pde is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:108002"/>
          <criterion comment="eclipse-swt is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:108916"/>
          <criterion comment="eclipse-rcp is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:108958"/>
          <criterion comment="eclipse-mylyn-pde is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:108669"/>
          <criterion comment="eclipse-mylyn-java is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:108813"/>
          <criterion comment="eclipse-mylyn is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:108982"/>
          <criterion comment="eclipse-mylyn-wikitext is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:108747"/>
          <criterion comment="eclipse-mylyn-webtasks is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:108881"/>
          <criterion comment="eclipse-mylyn-cdt is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:108607"/>
          <criterion comment="eclipse-mylyn-trac is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:108559"/>
          <criterion comment="eclipse-cdt is earlier than 1:7.0.1-4.el6" test_ref="oval:org.mitre.oval:tst:108471"/>
          <criterion comment="eclipse-cdt-parsers is earlier than 1:7.0.1-4.el6" test_ref="oval:org.mitre.oval:tst:108997"/>
          <criterion comment="eclipse-cdt-sdk is earlier than 1:7.0.1-4.el6" test_ref="oval:org.mitre.oval:tst:108596"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23520" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1120: haproxy security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>haproxy</product>
        </affected>
        <reference ref_id="ELSA-2013:1120-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1120.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2175" ref_url="http://linux.oracle.com/cve/CVE-2013-2175.html" source="CVE"/>
        <description>HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:06.731-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.483-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:04.742-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23520 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.938-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:37.755-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="haproxy is earlier than 0:1.4.22-5.el6_4" test_ref="oval:org.mitre.oval:tst:111508"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23519" version="21" class="patch">
      <metadata>
        <title>ELSA-2013:0730: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2013:0730-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0730.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1378" ref_url="http://linux.oracle.com/cve/CVE-2013-1378.html" source="CVE"/>
        <reference ref_id="CVE-2013-1379" ref_url="http://linux.oracle.com/cve/CVE-2013-1379.html" source="CVE"/>
        <reference ref_id="CVE-2013-1380" ref_url="http://linux.oracle.com/cve/CVE-2013-1380.html" source="CVE"/>
        <reference ref_id="CVE-2013-2555" ref_url="http://linux.oracle.com/cve/CVE-2013-2555.html" source="CVE"/>
        <description>Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK &amp; Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:45.707-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.373-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:04.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23519 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.304-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:37.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.280-2.el6" test_ref="oval:org.mitre.oval:tst:111870"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23518" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1202: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2012:1202-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1202.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3445" ref_url="http://linux.oracle.com/cve/CVE-2012-3445.html" source="CVE"/>
        <description>The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:37.040-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.307-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:04.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23518 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.108-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:37.495-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:110875"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:110980"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:109990"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:110714"/>
          <criterion comment="libvirt is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:110659"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23517" version="12" class="patch">
      <metadata>
        <title>ELSA-2014:0222: libtiff security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2014:0222-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0222.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2596" ref_url="http://linux.oracle.com/cve/CVE-2010-2596.html" source="CVE"/>
        <reference ref_id="CVE-2013-1960" ref_url="http://linux.oracle.com/cve/CVE-2013-1960.html" source="CVE"/>
        <reference ref_id="CVE-2013-1961" ref_url="http://linux.oracle.com/cve/CVE-2013-1961.html" source="CVE"/>
        <reference ref_id="CVE-2013-4231" ref_url="http://linux.oracle.com/cve/CVE-2013-4231.html" source="CVE"/>
        <reference ref_id="CVE-2013-4232" ref_url="http://linux.oracle.com/cve/CVE-2013-4232.html" source="CVE"/>
        <reference ref_id="CVE-2013-4243" ref_url="http://linux.oracle.com/cve/CVE-2013-4243.html" source="CVE"/>
        <reference ref_id="CVE-2013-4244" ref_url="http://linux.oracle.com/cve/CVE-2013-4244.html" source="CVE"/>
        <description>The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:44:29.238-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:05:04.112-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:07.138-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23517 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:22.426-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:58.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libtiff is earlier than 0:3.9.4-10.el6_5" test_ref="oval:org.mitre.oval:tst:112940"/>
          <criterion comment="libtiff-static is earlier than 0:3.9.4-10.el6_5" test_ref="oval:org.mitre.oval:tst:113421"/>
          <criterion comment="libtiff-devel is earlier than 0:3.9.4-10.el6_5" test_ref="oval:org.mitre.oval:tst:113686"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23516" version="15" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0310: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0310-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0310.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1493" ref_url="http://linux.oracle.com/cve/CVE-2014-1493.html" source="CVE"/>
        <reference ref_id="CVE-2014-1497" ref_url="http://linux.oracle.com/cve/CVE-2014-1497.html" source="CVE"/>
        <reference ref_id="CVE-2014-1505" ref_url="http://linux.oracle.com/cve/CVE-2014-1505.html" source="CVE"/>
        <reference ref_id="CVE-2014-1508" ref_url="http://linux.oracle.com/cve/CVE-2014-1508.html" source="CVE"/>
        <reference ref_id="CVE-2014-1509" ref_url="http://linux.oracle.com/cve/CVE-2014-1509.html" source="CVE"/>
        <reference ref_id="CVE-2014-1510" ref_url="http://linux.oracle.com/cve/CVE-2014-1510.html" source="CVE"/>
        <reference ref_id="CVE-2014-1511" ref_url="http://linux.oracle.com/cve/CVE-2014-1511.html" source="CVE"/>
        <reference ref_id="CVE-2014-1512" ref_url="http://linux.oracle.com/cve/CVE-2014-1512.html" source="CVE"/>
        <reference ref_id="CVE-2014-1513" ref_url="http://linux.oracle.com/cve/CVE-2014-1513.html" source="CVE"/>
        <reference ref_id="CVE-2014-1514" ref_url="http://linux.oracle.com/cve/CVE-2014-1514.html" source="CVE"/>
        <description>vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by triggering incorrect use of the TypedArrayObject class.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Sushant Kumar Singh</contributor>
            </submitted>
            <status_change date="2014-04-10T12:16:37.067-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:05:03.669-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:06.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23516 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:31.307-04:00">INTERIM</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:47:41.238-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:47:41.238-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113348"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:113511"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23515" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0369: python-sqlalchemy security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python-sqlalchemy</product>
        </affected>
        <reference ref_id="ELSA-2012:0369-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0369.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0805" ref_url="http://linux.oracle.com/cve/CVE-2012-0805.html" source="CVE"/>
        <description>Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:09.800-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.243-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:03.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23515 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.847-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:37.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="python-sqlalchemy is earlier than 0:0.5.5-3.el6_2" test_ref="oval:org.mitre.oval:tst:109330"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23514" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1272: libvirt security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference ref_id="ELSA-2013:1272-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1272.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4296" ref_url="http://linux.oracle.com/cve/CVE-2013-4296.html" source="CVE"/>
        <reference ref_id="CVE-2013-4311" ref_url="http://linux.oracle.com/cve/CVE-2013-4311.html" source="CVE"/>
        <description>libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:49:02.610-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.153-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:03.435-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23514 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:47.361-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:37.283-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:112427"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:112397"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:112436"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:111865"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:112331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23513" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0426: spice-xpi security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>spice-xpi</product>
        </affected>
        <reference ref_id="ELSA-2011:0426-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0426.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0012" ref_url="http://linux.oracle.com/cve/CVE-2011-0012.html" source="CVE"/>
        <reference ref_id="CVE-2011-1179" ref_url="http://linux.oracle.com/cve/CVE-2011-1179.html" source="CVE"/>
        <description>The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:28.506-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:18.071-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:03.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23513 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.492-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:37.161-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="spice-xpi is earlier than 0:2.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:108717"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23512" version="97" class="patch">
      <metadata>
        <title>ELSA-2011:0301: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference ref_id="ELSA-2011:0301-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0301.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0562" ref_url="http://linux.oracle.com/cve/CVE-2011-0562.html" source="CVE"/>
        <reference ref_id="CVE-2011-0563" ref_url="http://linux.oracle.com/cve/CVE-2011-0563.html" source="CVE"/>
        <reference ref_id="CVE-2011-0565" ref_url="http://linux.oracle.com/cve/CVE-2011-0565.html" source="CVE"/>
        <reference ref_id="CVE-2011-0566" ref_url="http://linux.oracle.com/cve/CVE-2011-0566.html" source="CVE"/>
        <reference ref_id="CVE-2011-0567" ref_url="http://linux.oracle.com/cve/CVE-2011-0567.html" source="CVE"/>
        <reference ref_id="CVE-2011-0585" ref_url="http://linux.oracle.com/cve/CVE-2011-0585.html" source="CVE"/>
        <reference ref_id="CVE-2011-0586" ref_url="http://linux.oracle.com/cve/CVE-2011-0586.html" source="CVE"/>
        <reference ref_id="CVE-2011-0587" ref_url="http://linux.oracle.com/cve/CVE-2011-0587.html" source="CVE"/>
        <reference ref_id="CVE-2011-0589" ref_url="http://linux.oracle.com/cve/CVE-2011-0589.html" source="CVE"/>
        <reference ref_id="CVE-2011-0590" ref_url="http://linux.oracle.com/cve/CVE-2011-0590.html" source="CVE"/>
        <reference ref_id="CVE-2011-0591" ref_url="http://linux.oracle.com/cve/CVE-2011-0591.html" source="CVE"/>
        <reference ref_id="CVE-2011-0592" ref_url="http://linux.oracle.com/cve/CVE-2011-0592.html" source="CVE"/>
        <reference ref_id="CVE-2011-0593" ref_url="http://linux.oracle.com/cve/CVE-2011-0593.html" source="CVE"/>
        <reference ref_id="CVE-2011-0594" ref_url="http://linux.oracle.com/cve/CVE-2011-0594.html" source="CVE"/>
        <reference ref_id="CVE-2011-0595" ref_url="http://linux.oracle.com/cve/CVE-2011-0595.html" source="CVE"/>
        <reference ref_id="CVE-2011-0596" ref_url="http://linux.oracle.com/cve/CVE-2011-0596.html" source="CVE"/>
        <reference ref_id="CVE-2011-0598" ref_url="http://linux.oracle.com/cve/CVE-2011-0598.html" source="CVE"/>
        <reference ref_id="CVE-2011-0599" ref_url="http://linux.oracle.com/cve/CVE-2011-0599.html" source="CVE"/>
        <reference ref_id="CVE-2011-0600" ref_url="http://linux.oracle.com/cve/CVE-2011-0600.html" source="CVE"/>
        <reference ref_id="CVE-2011-0602" ref_url="http://linux.oracle.com/cve/CVE-2011-0602.html" source="CVE"/>
        <reference ref_id="CVE-2011-0603" ref_url="http://linux.oracle.com/cve/CVE-2011-0603.html" source="CVE"/>
        <reference ref_id="CVE-2011-0604" ref_url="http://linux.oracle.com/cve/CVE-2011-0604.html" source="CVE"/>
        <reference ref_id="CVE-2011-0606" ref_url="http://linux.oracle.com/cve/CVE-2011-0606.html" source="CVE"/>
        <description>Stack-based buffer overflow in rt3d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors related to a crafted length value, a different vulnerability than CVE-2011-0563 and CVE-2011-0589.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:41.443-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:17.580-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:02.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23512 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.974-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:36.526-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.2-1.el5" test_ref="oval:org.mitre.oval:tst:108729"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.2-1.el5" test_ref="oval:org.mitre.oval:tst:108703"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="acroread is earlier than 0:9.4.2-3.el6_0" test_ref="oval:org.mitre.oval:tst:108667"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.2-3.el6_0" test_ref="oval:org.mitre.oval:tst:108421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23511" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0894: systemtap security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference ref_id="ELSA-2010:0894-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0894.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4170" ref_url="http://linux.oracle.com/cve/CVE-2010-4170.html" source="CVE"/>
        <reference ref_id="CVE-2010-4171" ref_url="http://linux.oracle.com/cve/CVE-2010-4171.html" source="CVE"/>
        <description>The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local users to cause a denial of service (unloading of arbitrary kernel modules).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:36.368-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:17.470-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:02.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23511 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.834-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:36.375-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="systemtap-client is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108173"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108312"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:107817"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108176"/>
            <criterion comment="systemtap is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108205"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108266"/>
            <criterion comment="systemtap-server is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:108025"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="systemtap-runtime is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:107915"/>
            <criterion comment="systemtap-client is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:107944"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:107878"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:108255"/>
            <criterion comment="systemtap is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:108144"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:108098"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:108282"/>
            <criterion comment="systemtap-server is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:107874"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23510" version="25" class="patch">
      <metadata>
        <title>ELSA-2010:0891: pam security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pam</product>
        </affected>
        <reference ref_id="ELSA-2010:0891-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0891.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3316" ref_url="http://linux.oracle.com/cve/CVE-2010-3316.html" source="CVE"/>
        <reference ref_id="CVE-2010-3435" ref_url="http://linux.oracle.com/cve/CVE-2010-3435.html" source="CVE"/>
        <reference ref_id="CVE-2010-3853" ref_url="http://linux.oracle.com/cve/CVE-2010-3853.html" source="CVE"/>
        <reference ref_id="CVE-2010-4707" ref_url="http://linux.oracle.com/cve/CVE-2010-4707.html" source="CVE"/>
        <reference ref_id="CVE-2010-4708" ref_url="http://linux.oracle.com/cve/CVE-2010-4708.html" source="CVE"/>
        <description>The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an unintended environment by executing a program that relies on the pam_env PAM check.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:33.405-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:17.337-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:01.901-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23510 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.877-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:36.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pam-devel is earlier than 0:1.1.1-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:108284"/>
          <criterion comment="pam is earlier than 0:1.1.1-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:108278"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23509" version="37" class="patch">
      <metadata>
        <title>ELSA-2011:0183: openoffice.org security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openoffice.org</product>
        </affected>
        <reference ref_id="ELSA-2011:0183-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0183.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3450" ref_url="http://linux.oracle.com/cve/CVE-2010-3450.html" source="CVE"/>
        <reference ref_id="CVE-2010-3451" ref_url="http://linux.oracle.com/cve/CVE-2010-3451.html" source="CVE"/>
        <reference ref_id="CVE-2010-3452" ref_url="http://linux.oracle.com/cve/CVE-2010-3452.html" source="CVE"/>
        <reference ref_id="CVE-2010-3453" ref_url="http://linux.oracle.com/cve/CVE-2010-3453.html" source="CVE"/>
        <reference ref_id="CVE-2010-3454" ref_url="http://linux.oracle.com/cve/CVE-2010-3454.html" source="CVE"/>
        <reference ref_id="CVE-2010-3689" ref_url="http://linux.oracle.com/cve/CVE-2010-3689.html" source="CVE"/>
        <reference ref_id="CVE-2010-4253" ref_url="http://linux.oracle.com/cve/CVE-2010-4253.html" source="CVE"/>
        <reference ref_id="CVE-2010-4643" ref_url="http://linux.oracle.com/cve/CVE-2010-4643.html" source="CVE"/>
        <description>Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:38.956-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:16.865-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:00.968-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23509 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:43.238-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:35.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108215"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108308"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108327"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108404"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108386"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107871"/>
          <criterion comment="autocorr-af is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108109"/>
          <criterion comment="openoffice.org-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108235"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108023"/>
          <criterion comment="openoffice.org-langpack-dz is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108133"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108377"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108175"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108380"/>
          <criterion comment="broffice.org-brand is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108389"/>
          <criterion comment="autocorr-vi is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108334"/>
          <criterion comment="openoffice.org-langpack-uk is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108313"/>
          <criterion comment="autocorr-ja is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107893"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108140"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108426"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108417"/>
          <criterion comment="openoffice.org-calc is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108257"/>
          <criterion comment="openoffice.org-opensymbol-fonts is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108245"/>
          <criterion comment="autocorr-eu is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108410"/>
          <criterion comment="openoffice.org is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108345"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108359"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108166"/>
          <criterion comment="openoffice.org-presentation-minimizer is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108391"/>
          <criterion comment="autocorr-sl is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108325"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108247"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108342"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107981"/>
          <criterion comment="openoffice.org-calc-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108156"/>
          <criterion comment="openoffice.org-draw is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108484"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108238"/>
          <criterion comment="openoffice.org-devel is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108299"/>
          <criterion comment="autocorr-ga is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108434"/>
          <criterion comment="openoffice.org-report-builder is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108285"/>
          <criterion comment="autocorr-mn is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108268"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108208"/>
          <criterion comment="broffice.org-math is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108344"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108336"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107522"/>
          <criterion comment="autocorr-pl is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108090"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107958"/>
          <criterion comment="openoffice.org-base-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108330"/>
          <criterion comment="broffice.org-writer is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108318"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108346"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107918"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108179"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108449"/>
          <criterion comment="openoffice.org-brand is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108059"/>
          <criterion comment="broffice.org-impress is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107798"/>
          <criterion comment="autocorr-da is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107538"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108067"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108460"/>
          <criterion comment="openoffice.org-langpack-pa is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108394"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108337"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107474"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108387"/>
          <criterion comment="openoffice.org-writer is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108329"/>
          <criterion comment="broffice.org-calc is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107721"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108405"/>
          <criterion comment="autocorr-tr is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108388"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108095"/>
          <criterion comment="autocorr-sv is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108431"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108152"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108169"/>
          <criterion comment="autocorr-fr is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108351"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108078"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108040"/>
          <criterion comment="autocorr-es is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108164"/>
          <criterion comment="openoffice.org-langpack-en is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107954"/>
          <criterion comment="openoffice.org-langpack-ro is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108274"/>
          <criterion comment="autocorr-fi is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107530"/>
          <criterion comment="openoffice.org-impress is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108276"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108350"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108367"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108153"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108357"/>
          <criterion comment="openoffice.org-langpack-mai_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108301"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107504"/>
          <criterion comment="openoffice.org-wiki-publisher is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108452"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108046"/>
          <criterion comment="autocorr-de is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107452"/>
          <criterion comment="broffice.org-base is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108358"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108265"/>
          <criterion comment="openoffice.org-math is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107868"/>
          <criterion comment="autocorr-nl is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108183"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107749"/>
          <criterion comment="openoffice.org-draw-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108444"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107805"/>
          <criterion comment="autocorr-bg is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108343"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108212"/>
          <criterion comment="openoffice.org-bsh is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107794"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108486"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108230"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108076"/>
          <criterion comment="openoffice.org-langpack-sr is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108089"/>
          <criterion comment="openoffice.org-math-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107510"/>
          <criterion comment="autocorr-ru is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108323"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108155"/>
          <criterion comment="autocorr-en is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108355"/>
          <criterion comment="autocorr-sk is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107636"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108131"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108503"/>
          <criterion comment="autocorr-pt is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108446"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108418"/>
          <criterion comment="openoffice.org-writer-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108324"/>
          <criterion comment="autocorr-lt is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107710"/>
          <criterion comment="autocorr-cs is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107983"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108297"/>
          <criterion comment="openoffice.org-rhino is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108120"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108158"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108174"/>
          <criterion comment="openoffice.org-presenter-screen is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108137"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108383"/>
          <criterion comment="openoffice.org-impress-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108149"/>
          <criterion comment="autocorr-fa is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108234"/>
          <criterion comment="broffice.org-draw is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108436"/>
          <criterion comment="openoffice.org-pdfimport is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108224"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108341"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108271"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108254"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108277"/>
          <criterion comment="autocorr-zh is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107977"/>
          <criterion comment="autocorr-ko is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108331"/>
          <criterion comment="openoffice.org-headless is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107675"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108223"/>
          <criterion comment="autocorr-it is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108320"/>
          <criterion comment="openoffice.org-ogltrans is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107800"/>
          <criterion comment="openoffice.org-base is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108487"/>
          <criterion comment="autocorr-hu is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108091"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108435"/>
          <criterion comment="autocorr-lb is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108419"/>
          <criterion comment="openoffice.org-ure is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:107844"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:108413"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23508" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0910: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2011:0910-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0910.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0188" ref_url="http://linux.oracle.com/cve/CVE-2011-0188.html" source="CVE"/>
        <reference ref_id="CVE-2011-1004" ref_url="http://linux.oracle.com/cve/CVE-2011-1004.html" source="CVE"/>
        <reference ref_id="CVE-2011-1005" ref_url="http://linux.oracle.com/cve/CVE-2011-1005.html" source="CVE"/>
        <description>The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:11.973-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:16.745-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:00.712-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23508 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.900-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:35.353-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ruby is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:108769"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:109031"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:108947"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:108963"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:108198"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:109045"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:108999"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:109100"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:109071"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23507" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0842: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference ref_id="ELSA-2011:0842-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0842.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1769" ref_url="http://linux.oracle.com/cve/CVE-2011-1769.html" source="CVE"/>
        <reference ref_id="CVE-2011-1781" ref_url="http://linux.oracle.com/cve/CVE-2011-1781.html" source="CVE"/>
        <description>SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs stack unwinding (aka backtracing).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:39.692-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:16.621-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:00.555-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23507 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:43.799-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:35.213-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="systemtap-runtime is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:108984"/>
          <criterion comment="systemtap-client is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:108573"/>
          <criterion comment="systemtap-testsuite is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:108585"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:109004"/>
          <criterion comment="systemtap is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:109009"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:108759"/>
          <criterion comment="systemtap-grapher is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:108851"/>
          <criterion comment="systemtap-server is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:108987"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23506" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1475: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2013:1475-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1475.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0255" ref_url="http://linux.oracle.com/cve/CVE-2013-0255.html" source="CVE"/>
        <reference ref_id="CVE-2013-1000" ref_url="http://linux.oracle.com/cve/CVE-2013-1000.html" source="CVE"/>
        <description>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:23.432-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:16.440-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:00.352-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23506 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:41.771-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:35.044-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:47:10.276-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:47:10.276-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql-devel is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107559"/>
            <criterion comment="postgresql is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107665"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107735"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107813"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107618"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107582"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107149"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107384"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107528"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:107659"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107408"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107680"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107832"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107593"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107492"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107679"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107557"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107828"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:106856"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107764"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107747"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:107426"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23505" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1777: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference ref_id="ELSA-2011:1777-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1777.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4111" ref_url="http://linux.oracle.com/cve/CVE-2011-4111.html" source="CVE"/>
        <description>Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:55.769-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:16.367-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:05:00.243-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23505 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.771-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:34.935-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.209.el6_2.1" test_ref="oval:org.mitre.oval:tst:109527"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.209.el6_2.1" test_ref="oval:org.mitre.oval:tst:109589"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.209.el6_2.1" test_ref="oval:org.mitre.oval:tst:109638"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23504" version="25" class="patch">
      <metadata>
        <title>ELSA-2012:0079: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:0079-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0079.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3659" ref_url="http://linux.oracle.com/cve/CVE-2011-3659.html" source="CVE"/>
        <reference ref_id="CVE-2011-3670" ref_url="http://linux.oracle.com/cve/CVE-2011-3670.html" source="CVE"/>
        <reference ref_id="CVE-2012-0442" ref_url="http://linux.oracle.com/cve/CVE-2012-0442.html" source="CVE"/>
        <reference ref_id="CVE-2012-0444" ref_url="http://linux.oracle.com/cve/CVE-2012-0444.html" source="CVE"/>
        <reference ref_id="CVE-2012-0449" ref_url="http://linux.oracle.com/cve/CVE-2012-0449.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:17.195-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:16.166-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:59.990-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23504 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.321-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:34.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:109403"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:109729"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:109565"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:109807"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:109364"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:109464"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23502" version="17" class="patch">
      <metadata>
        <title>ELSA-2010:0925: krb5 security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2010:0925-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0925.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1323" ref_url="http://linux.oracle.com/cve/CVE-2010-1323.html" source="CVE"/>
        <reference ref_id="CVE-2010-1324" ref_url="http://linux.oracle.com/cve/CVE-2010-1324.html" source="CVE"/>
        <reference ref_id="CVE-2010-4020" ref_url="http://linux.oracle.com/cve/CVE-2010-4020.html" source="CVE"/>
        <description>MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC-ISSUED signature, and possibly gain privileges, by leveraging the small key space that results from certain one-byte stream-cipher operations.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:30.742-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.975-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:59.791-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23502 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.211-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:34.546-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:108197"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:108280"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:108114"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:107881"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:108262"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:108035"/>
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:108178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23500" version="25" class="patch">
      <metadata>
        <title>ELSA-2011:1341: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:1341-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1341.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2372" ref_url="http://linux.oracle.com/cve/CVE-2011-2372.html" source="CVE"/>
        <reference ref_id="CVE-2011-2995" ref_url="http://linux.oracle.com/cve/CVE-2011-2995.html" source="CVE"/>
        <reference ref_id="CVE-2011-2998" ref_url="http://linux.oracle.com/cve/CVE-2011-2998.html" source="CVE"/>
        <reference ref_id="CVE-2011-2999" ref_url="http://linux.oracle.com/cve/CVE-2011-2999.html" source="CVE"/>
        <reference ref_id="CVE-2011-3000" ref_url="http://linux.oracle.com/cve/CVE-2011-3000.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:04.330-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.733-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:59.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23500 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.782-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:34.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:108948"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:109310"/>
            <criterion comment="firefox is earlier than 0:3.6.23-2.el5_7" test_ref="oval:org.mitre.oval:tst:109124"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="firefox is earlier than 0:3.6.23-2.el6_1" test_ref="oval:org.mitre.oval:tst:109393"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:109412"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:109417"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23499" version="21" class="patch">
      <metadata>
        <title>ELSA-2010:0892: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2010:0892-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0892.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3302" ref_url="http://linux.oracle.com/cve/CVE-2010-3302.html" source="CVE"/>
        <reference ref_id="CVE-2010-3308" ref_url="http://linux.oracle.com/cve/CVE-2010-3308.html" source="CVE"/>
        <reference ref_id="CVE-2010-3752" ref_url="http://linux.oracle.com/cve/CVE-2010-3752.html" source="CVE"/>
        <reference ref_id="CVE-2010-3753" ref_url="http://linux.oracle.com/cve/CVE-2010-3753.html" source="CVE"/>
        <description>programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in the cisco_banner (aka server_banner) field, a different vulnerability than CVE-2010-3308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:35.475-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.616-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:59.110-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23499 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.217-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:33.935-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openswan is earlier than 0:2.6.24-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:108009"/>
          <criterion comment="openswan-doc is earlier than 0:2.6.24-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:107787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23498" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0771: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2013:0771-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0771.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1944" ref_url="http://linux.oracle.com/cve/CVE-2013-1944.html" source="CVE"/>
        <description>The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:40.996-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.549-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:58.986-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23498 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.780-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:33.799-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:45:26.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:45:26.232-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:107208"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:107365"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:107420"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:107076"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:107057"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23497" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0813: 389-ds-base security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference ref_id="ELSA-2012:0813-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0813.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0833" ref_url="http://linux.oracle.com/cve/CVE-2012-0833.html" source="CVE"/>
        <description>The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:33.202-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.480-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:58.887-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23497 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.505-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:33.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="389-ds-base is earlier than 0:1.2.10.2-15.el6" test_ref="oval:org.mitre.oval:tst:110401"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.10.2-15.el6" test_ref="oval:org.mitre.oval:tst:110298"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.10.2-15.el6" test_ref="oval:org.mitre.oval:tst:110224"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23495" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1422: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>openswan</product>
        </affected>
        <reference ref_id="ELSA-2011:1422-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1422.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4073" ref_url="http://linux.oracle.com/cve/CVE-2011-4073.html" source="CVE"/>
        <description>Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:13.821-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.412-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:58.780-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23495 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.215-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:33.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:109260"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:109467"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:109326"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:109473"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23494" version="21" class="patch">
      <metadata>
        <title>ELSA-2010:0864: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference ref_id="ELSA-2010:0864-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0864.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2805" ref_url="http://linux.oracle.com/cve/CVE-2010-2805.html" source="CVE"/>
        <reference ref_id="CVE-2010-2806" ref_url="http://linux.oracle.com/cve/CVE-2010-2806.html" source="CVE"/>
        <reference ref_id="CVE-2010-2808" ref_url="http://linux.oracle.com/cve/CVE-2010-2808.html" source="CVE"/>
        <reference ref_id="CVE-2010-3311" ref_url="http://linux.oracle.com/cve/CVE-2010-3311.html" source="CVE"/>
        <description>Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:33.892-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:15.293-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:58.567-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23494 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.727-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:33.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108001"/>
          <criterion comment="freetype is earlier than 0:2.3.11-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:107861"/>
          <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:107167"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23493" version="86" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0770: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0770-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0770.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0401" ref_url="http://linux.oracle.com/cve/CVE-2013-0401.html" source="CVE"/>
        <reference ref_id="CVE-2013-1488" ref_url="http://linux.oracle.com/cve/CVE-2013-1488.html" source="CVE"/>
        <reference ref_id="CVE-2013-1518" ref_url="http://linux.oracle.com/cve/CVE-2013-1518.html" source="CVE"/>
        <reference ref_id="CVE-2013-1537" ref_url="http://linux.oracle.com/cve/CVE-2013-1537.html" source="CVE"/>
        <reference ref_id="CVE-2013-1557" ref_url="http://linux.oracle.com/cve/CVE-2013-1557.html" source="CVE"/>
        <reference ref_id="CVE-2013-1558" ref_url="http://linux.oracle.com/cve/CVE-2013-1558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1569" ref_url="http://linux.oracle.com/cve/CVE-2013-1569.html" source="CVE"/>
        <reference ref_id="CVE-2013-2383" ref_url="http://linux.oracle.com/cve/CVE-2013-2383.html" source="CVE"/>
        <reference ref_id="CVE-2013-2384" ref_url="http://linux.oracle.com/cve/CVE-2013-2384.html" source="CVE"/>
        <reference ref_id="CVE-2013-2415" ref_url="http://linux.oracle.com/cve/CVE-2013-2415.html" source="CVE"/>
        <reference ref_id="CVE-2013-2417" ref_url="http://linux.oracle.com/cve/CVE-2013-2417.html" source="CVE"/>
        <reference ref_id="CVE-2013-2419" ref_url="http://linux.oracle.com/cve/CVE-2013-2419.html" source="CVE"/>
        <reference ref_id="CVE-2013-2420" ref_url="http://linux.oracle.com/cve/CVE-2013-2420.html" source="CVE"/>
        <reference ref_id="CVE-2013-2421" ref_url="http://linux.oracle.com/cve/CVE-2013-2421.html" source="CVE"/>
        <reference ref_id="CVE-2013-2422" ref_url="http://linux.oracle.com/cve/CVE-2013-2422.html" source="CVE"/>
        <reference ref_id="CVE-2013-2424" ref_url="http://linux.oracle.com/cve/CVE-2013-2424.html" source="CVE"/>
        <reference ref_id="CVE-2013-2426" ref_url="http://linux.oracle.com/cve/CVE-2013-2426.html" source="CVE"/>
        <reference ref_id="CVE-2013-2429" ref_url="http://linux.oracle.com/cve/CVE-2013-2429.html" source="CVE"/>
        <reference ref_id="CVE-2013-2430" ref_url="http://linux.oracle.com/cve/CVE-2013-2430.html" source="CVE"/>
        <reference ref_id="CVE-2013-2431" ref_url="http://linux.oracle.com/cve/CVE-2013-2431.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to bypassing the Java sandbox using "method handle intrinsic frames."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:42.574-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.843-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:57.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23493 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.499-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.844-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:44:43.046-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:44:43.046-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:106958"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:107424"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:107457"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:107410"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:106957"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107006"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107154"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107433"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107189"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:107013"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23492" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:1003: git security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>git</product>
        </affected>
        <reference ref_id="ELSA-2010:1003-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-1003.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3906" ref_url="http://linux.oracle.com/cve/CVE-2010-3906.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:34.981-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.744-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:57.651-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23492 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.321-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="git-cvs is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108286"/>
          <criterion comment="emacs-git-el is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108252"/>
          <criterion comment="git-email is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:107524"/>
          <criterion comment="gitk is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:107934"/>
          <criterion comment="git-daemon is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108033"/>
          <criterion comment="git-svn is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108070"/>
          <criterion comment="git-all is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108199"/>
          <criterion comment="git-gui is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108139"/>
          <criterion comment="emacs-git is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108049"/>
          <criterion comment="gitweb is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108307"/>
          <criterion comment="git is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:107889"/>
          <criterion comment="perl-Git is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108236"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23490" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:1282: rtkit security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>rtkit</product>
        </affected>
        <reference ref_id="ELSA-2013:1282-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1282.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4326" ref_url="http://linux.oracle.com/cve/CVE-2013-4326.html" source="CVE"/>
        <description>RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:08.677-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.557-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:57.318-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23490 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:41.658-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.427-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="rtkit is earlier than 0:0.5-2.el6_4" test_ref="oval:org.mitre.oval:tst:112357"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23489" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0587: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2013:0587-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0587.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4929" ref_url="http://linux.oracle.com/cve/CVE-2012-4929.html" source="CVE"/>
        <reference ref_id="CVE-2013-0166" ref_url="http://linux.oracle.com/cve/CVE-2013-0166.html" source="CVE"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <description>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:01.790-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.437-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:57.131-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23489 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:41.330-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.297-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:43:47.262-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:43:47.262-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:106258"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:107214"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:106990"/>
            <criterion comment="openssl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:107182"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:107117"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:106825"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:107131"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23487" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0883: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2013:0883-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0883.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2116" ref_url="http://linux.oracle.com/cve/CVE-2013-2116.html" source="CVE"/>
        <description>The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length.  NOTE: this might be due to an incorrect fix for CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:36.116-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.263-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:56.879-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23487 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.402-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:32.091-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:107534"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:107569"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:107352"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:107494"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:107425"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:107400"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:107318"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23485" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0890: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference ref_id="ELSA-2010:0890-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0890.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3711" ref_url="http://linux.oracle.com/cve/CVE-2010-3711.html" source="CVE"/>
        <description>libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:29.768-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:14.084-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:56.650-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23485 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:41.901-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:31.859-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pidgin-docs is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:107552"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:107499"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:108111"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:108053"/>
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:107315"/>
          <criterion comment="finch-devel is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:107887"/>
          <criterion comment="finch is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:107775"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:108075"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:108127"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:108188"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23484" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0532: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference ref_id="ELSA-2013:0532-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0532.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0169" ref_url="http://linux.oracle.com/cve/CVE-2013-0169.html" source="CVE"/>
        <reference ref_id="CVE-2013-1484" ref_url="http://linux.oracle.com/cve/CVE-2013-1484.html" source="CVE"/>
        <reference ref_id="CVE-2013-1485" ref_url="http://linux.oracle.com/cve/CVE-2013-1485.html" source="CVE"/>
        <reference ref_id="CVE-2013-1486" ref_url="http://linux.oracle.com/cve/CVE-2013-1486.html" source="CVE"/>
        <reference ref_id="CVE-2013-1487" ref_url="http://linux.oracle.com/cve/CVE-2013-1487.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 and earlier and 6 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:37.143-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:13.923-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:56.395-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23484 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:46.407-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:31.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111621"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111514"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111279"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111306"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111351"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111158"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23483" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0983: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference ref_id="ELSA-2013:0983-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0983.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2174" ref_url="http://linux.oracle.com/cve/CVE-2013-2174.html" source="CVE"/>
        <description>Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:45.778-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:13.847-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:56.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23483 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:42.482-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:31.539-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:42:58.917-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:42:58.917-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:107253"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:106843"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:107585"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="curl is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:107567"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:107370"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23482" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1806: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference ref_id="ELSA-2013:1806-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1806.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4408" ref_url="http://linux.oracle.com/cve/CVE-2013-4408.html" source="CVE"/>
        <reference ref_id="CVE-2013-4475" ref_url="http://linux.oracle.com/cve/CVE-2013-4475.html" source="CVE"/>
        <description>Samba 3.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:28.531-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:13.714-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:56.100-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23482 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:44.629-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:31.344-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:42:18.229-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:42:18.229-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107549"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107922"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107138"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107821"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107951"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107766"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107965"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:107694"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="samba-common is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107894"/>
            <criterion comment="samba is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107908"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107357"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107625"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107696"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107911"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107875"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107900"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107949"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107880"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107768"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:107536"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23481" version="45" class="patch">
      <metadata>
        <title>ELSA-2013:0982: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2013:0982-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0982.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1682" ref_url="http://linux.oracle.com/cve/CVE-2013-1682.html" source="CVE"/>
        <reference ref_id="CVE-2013-1684" ref_url="http://linux.oracle.com/cve/CVE-2013-1684.html" source="CVE"/>
        <reference ref_id="CVE-2013-1685" ref_url="http://linux.oracle.com/cve/CVE-2013-1685.html" source="CVE"/>
        <reference ref_id="CVE-2013-1686" ref_url="http://linux.oracle.com/cve/CVE-2013-1686.html" source="CVE"/>
        <reference ref_id="CVE-2013-1687" ref_url="http://linux.oracle.com/cve/CVE-2013-1687.html" source="CVE"/>
        <reference ref_id="CVE-2013-1690" ref_url="http://linux.oracle.com/cve/CVE-2013-1690.html" source="CVE"/>
        <reference ref_id="CVE-2013-1692" ref_url="http://linux.oracle.com/cve/CVE-2013-1692.html" source="CVE"/>
        <reference ref_id="CVE-2013-1693" ref_url="http://linux.oracle.com/cve/CVE-2013-1693.html" source="CVE"/>
        <reference ref_id="CVE-2013-1694" ref_url="http://linux.oracle.com/cve/CVE-2013-1694.html" source="CVE"/>
        <reference ref_id="CVE-2013-1697" ref_url="http://linux.oracle.com/cve/CVE-2013-1697.html" source="CVE"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:57.160-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:13.469-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:55.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23481 - optimisation of Oracle Linux content" date="2014-05-05T17:35:00.742-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:37:45.108-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:30.968-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:107205"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:107471"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23479" version="21" class="patch">
      <metadata>
        <title>ELSA-2011:0195: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2011:0195-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0195.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-5016" ref_url="http://linux.oracle.com/cve/CVE-2009-5016.html" source="CVE"/>
        <reference ref_id="CVE-2010-3709" ref_url="http://linux.oracle.com/cve/CVE-2010-3709.html" source="CVE"/>
        <reference ref_id="CVE-2010-3870" ref_url="http://linux.oracle.com/cve/CVE-2010-3870.html" source="CVE"/>
        <reference ref_id="CVE-2010-4645" ref_url="http://linux.oracle.com/cve/CVE-2010-4645.html" source="CVE"/>
        <description>strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:30.524-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:12.906-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:54.774-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23479 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:26.645-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:57.865-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php-pdo is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108532"/>
          <criterion comment="php-common is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108406"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108123"/>
          <criterion comment="php-embedded is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108492"/>
          <criterion comment="php-snmp is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108159"/>
          <criterion comment="php-enchant is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108283"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108502"/>
          <criterion comment="php-recode is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108465"/>
          <criterion comment="php-devel is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108077"/>
          <criterion comment="php is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108439"/>
          <criterion comment="php-gd is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108248"/>
          <criterion comment="php-imap is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108455"/>
          <criterion comment="php-odbc is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108311"/>
          <criterion comment="php-soap is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108154"/>
          <criterion comment="php-tidy is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108379"/>
          <criterion comment="php-mysql is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:107541"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108087"/>
          <criterion comment="php-zts is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:107630"/>
          <criterion comment="php-intl is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108541"/>
          <criterion comment="php-process is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108093"/>
          <criterion comment="php-ldap is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:107890"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108480"/>
          <criterion comment="php-dba is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108126"/>
          <criterion comment="php-cli is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108473"/>
          <criterion comment="php-pspell is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:107829"/>
          <criterion comment="php-xml is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:108202"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23478" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0942: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2013:0942-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0942.html" source="VENDOR"/>
        <reference ref_id="CVE-2002-2443" ref_url="http://linux.oracle.com/cve/CVE-2002-2443.html" source="CVE"/>
        <description>schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:38.302-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:12.822-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:54.623-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23478 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.597-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:30.317-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:40:42.798-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:40:42.798-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107312"/>
            <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107496"/>
            <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:106642"/>
            <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107487"/>
            <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107572"/>
            <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:106921"/>
            <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:107311"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107102"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107156"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107548"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107293"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107421"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:107356"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23476" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1245: httpd security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2011:1245-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1245.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3192" ref_url="http://linux.oracle.com/cve/CVE-2011-3192.html" source="CVE"/>
        <description>The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:22.515-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:12.725-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:54.491-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23476 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.984-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:30.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:109151"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:109143"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:108420"/>
            <criterion comment="httpd is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:108892"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109187"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109175"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109058"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:108991"/>
            <criterion comment="httpd is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:109158"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23475" version="85" class="patch">
      <metadata>
        <title>ELSA-2012:1351: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:1351-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1351.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1956" ref_url="http://linux.oracle.com/cve/CVE-2012-1956.html" source="CVE"/>
        <reference ref_id="CVE-2012-3982" ref_url="http://linux.oracle.com/cve/CVE-2012-3982.html" source="CVE"/>
        <reference ref_id="CVE-2012-3986" ref_url="http://linux.oracle.com/cve/CVE-2012-3986.html" source="CVE"/>
        <reference ref_id="CVE-2012-3988" ref_url="http://linux.oracle.com/cve/CVE-2012-3988.html" source="CVE"/>
        <reference ref_id="CVE-2012-3990" ref_url="http://linux.oracle.com/cve/CVE-2012-3990.html" source="CVE"/>
        <reference ref_id="CVE-2012-3991" ref_url="http://linux.oracle.com/cve/CVE-2012-3991.html" source="CVE"/>
        <reference ref_id="CVE-2012-3992" ref_url="http://linux.oracle.com/cve/CVE-2012-3992.html" source="CVE"/>
        <reference ref_id="CVE-2012-3993" ref_url="http://linux.oracle.com/cve/CVE-2012-3993.html" source="CVE"/>
        <reference ref_id="CVE-2012-3994" ref_url="http://linux.oracle.com/cve/CVE-2012-3994.html" source="CVE"/>
        <reference ref_id="CVE-2012-3995" ref_url="http://linux.oracle.com/cve/CVE-2012-3995.html" source="CVE"/>
        <reference ref_id="CVE-2012-4179" ref_url="http://linux.oracle.com/cve/CVE-2012-4179.html" source="CVE"/>
        <reference ref_id="CVE-2012-4180" ref_url="http://linux.oracle.com/cve/CVE-2012-4180.html" source="CVE"/>
        <reference ref_id="CVE-2012-4181" ref_url="http://linux.oracle.com/cve/CVE-2012-4181.html" source="CVE"/>
        <reference ref_id="CVE-2012-4182" ref_url="http://linux.oracle.com/cve/CVE-2012-4182.html" source="CVE"/>
        <reference ref_id="CVE-2012-4183" ref_url="http://linux.oracle.com/cve/CVE-2012-4183.html" source="CVE"/>
        <reference ref_id="CVE-2012-4184" ref_url="http://linux.oracle.com/cve/CVE-2012-4184.html" source="CVE"/>
        <reference ref_id="CVE-2012-4185" ref_url="http://linux.oracle.com/cve/CVE-2012-4185.html" source="CVE"/>
        <reference ref_id="CVE-2012-4186" ref_url="http://linux.oracle.com/cve/CVE-2012-4186.html" source="CVE"/>
        <reference ref_id="CVE-2012-4187" ref_url="http://linux.oracle.com/cve/CVE-2012-4187.html" source="CVE"/>
        <reference ref_id="CVE-2012-4188" ref_url="http://linux.oracle.com/cve/CVE-2012-4188.html" source="CVE"/>
        <description>Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:08.037-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:12.314-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:53.673-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23475 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.743-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:29.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:111235"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:111199"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23474" version="70" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1482: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1482-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1482.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4201" ref_url="http://linux.oracle.com/cve/CVE-2012-4201.html" source="CVE"/>
        <reference ref_id="CVE-2012-4202" ref_url="http://linux.oracle.com/cve/CVE-2012-4202.html" source="CVE"/>
        <reference ref_id="CVE-2012-4207" ref_url="http://linux.oracle.com/cve/CVE-2012-4207.html" source="CVE"/>
        <reference ref_id="CVE-2012-4209" ref_url="http://linux.oracle.com/cve/CVE-2012-4209.html" source="CVE"/>
        <reference ref_id="CVE-2012-4210" ref_url="http://linux.oracle.com/cve/CVE-2012-4210.html" source="CVE"/>
        <reference ref_id="CVE-2012-4214" ref_url="http://linux.oracle.com/cve/CVE-2012-4214.html" source="CVE"/>
        <reference ref_id="CVE-2012-4215" ref_url="http://linux.oracle.com/cve/CVE-2012-4215.html" source="CVE"/>
        <reference ref_id="CVE-2012-4216" ref_url="http://linux.oracle.com/cve/CVE-2012-4216.html" source="CVE"/>
        <reference ref_id="CVE-2012-5829" ref_url="http://linux.oracle.com/cve/CVE-2012-5829.html" source="CVE"/>
        <reference ref_id="CVE-2012-5830" ref_url="http://linux.oracle.com/cve/CVE-2012-5830.html" source="CVE"/>
        <reference ref_id="CVE-2012-5833" ref_url="http://linux.oracle.com/cve/CVE-2012-5833.html" source="CVE"/>
        <reference ref_id="CVE-2012-5835" ref_url="http://linux.oracle.com/cve/CVE-2012-5835.html" source="CVE"/>
        <reference ref_id="CVE-2012-5839" ref_url="http://linux.oracle.com/cve/CVE-2012-5839.html" source="CVE"/>
        <reference ref_id="CVE-2012-5840" ref_url="http://linux.oracle.com/cve/CVE-2012-5840.html" source="CVE"/>
        <reference ref_id="CVE-2012-5841" ref_url="http://linux.oracle.com/cve/CVE-2012-5841.html" source="CVE"/>
        <reference ref_id="CVE-2012-5842" ref_url="http://linux.oracle.com/cve/CVE-2012-5842.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:39.445-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.941-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.992-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23474 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.222-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:29.179-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:39:34.264-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:39:34.264-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106943"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106846"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:106944"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:106628"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:106742"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:107022"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23473" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0554: python security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>python</product>
          <product>python-docs</product>
        </affected>
        <reference ref_id="ELSA-2011:0554-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0554.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3493" ref_url="http://linux.oracle.com/cve/CVE-2010-3493.html" source="CVE"/>
        <reference ref_id="CVE-2011-1015" ref_url="http://linux.oracle.com/cve/CVE-2011-1015.html" source="CVE"/>
        <reference ref_id="CVE-2011-1521" ref_url="http://linux.oracle.com/cve/CVE-2011-1521.html" source="CVE"/>
        <description>The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:31.428-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.829-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.791-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23473 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.697-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:29.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="python-docs is earlier than 0:2.6.6-2.el6" test_ref="oval:org.mitre.oval:tst:108407"/>
          <criterion comment="python-devel is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:108946"/>
          <criterion comment="python-test is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:108402"/>
          <criterion comment="tkinter is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:108775"/>
          <criterion comment="python is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:108356"/>
          <criterion comment="python-libs is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:108218"/>
          <criterion comment="python-tools is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:108873"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23472" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0318: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference ref_id="ELSA-2011:0318-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0318.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0192" ref_url="http://linux.oracle.com/cve/CVE-2011-0192.html" source="CVE"/>
        <description>Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding, related to the EXPAND2D macro in libtiff/tif_fax3.h.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:28.892-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.752-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23472 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.459-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libtiff is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108453"/>
          <criterion comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108512"/>
          <criterion comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108736"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23471" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:1151: openldap security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference ref_id="ELSA-2012:1151-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1151.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2668" ref_url="http://linux.oracle.com/cve/CVE-2012-2668.html" source="CVE"/>
        <description>libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:43.541-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.682-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.530-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23471 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.875-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.823-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openldap-servers is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:110882"/>
          <criterion comment="openldap is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:110767"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:110847"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:110946"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:110780"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23470" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1459: gnupg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnupg2</product>
        </affected>
        <reference ref_id="ELSA-2013:1459-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1459.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-6085" ref_url="http://linux.oracle.com/cve/CVE-2012-6085.html" source="CVE"/>
        <reference ref_id="CVE-2013-4351" ref_url="http://linux.oracle.com/cve/CVE-2013-4351.html" source="CVE"/>
        <reference ref_id="CVE-2013-4402" ref_url="http://linux.oracle.com/cve/CVE-2013-4402.html" source="CVE"/>
        <description>The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:34.507-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.628-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.443-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23470 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.872-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.738-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:38:50.654-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:38:50.654-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnupg2 is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:107207"/>
            <criterion comment="gnupg2-smime is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:106836"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="gnupg2 is earlier than 0:2.0.10-6.el5_10" test_ref="oval:org.mitre.oval:tst:106842"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23468" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0958: sos security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>sos</product>
        </affected>
        <reference ref_id="ELSA-2012:0958-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0958.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2664" ref_url="http://linux.oracle.com/cve/CVE-2012-2664.html" source="CVE"/>
        <description>The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:23.517-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.485-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.339-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23468 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.557-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="sos is earlier than 0:2.2-29.el6" test_ref="oval:org.mitre.oval:tst:110506"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23467" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0568: dbus-glib security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dbus-glib</product>
        </affected>
        <reference ref_id="ELSA-2013:0568-03" ref_url="http://linux.oracle.com/errata/ELSA-2013-0568.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0292" ref_url="http://linux.oracle.com/cve/CVE-2013-0292.html" source="CVE"/>
        <description>The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:56.606-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.410-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.237-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23467 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.359-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.507-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:38:15.846-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:38:15.846-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:106987"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:106995"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dbus-glib is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:106772"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:107082"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23466" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:1180: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference ref_id="ELSA-2012:1180-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1180.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2896" ref_url="http://linux.oracle.com/cve/CVE-2011-2896.html" source="CVE"/>
        <reference ref_id="CVE-2012-3403" ref_url="http://linux.oracle.com/cve/CVE-2012-3403.html" source="CVE"/>
        <reference ref_id="CVE-2012-3481" ref_url="http://linux.oracle.com/cve/CVE-2012-3481.html" source="CVE"/>
        <description>Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height and len properties in a GIF image file, which triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:37:40.136-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.303-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:52.051-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23466 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.064-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="gimp-libs is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:110940"/>
          <criterion comment="gimp-devel is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:110814"/>
          <criterion comment="gimp-help-browser is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:110613"/>
          <criterion comment="gimp is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:110906"/>
          <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:110838"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23465" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0815: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>httpd</product>
        </affected>
        <reference ref_id="ELSA-2013:0815-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0815.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3499" ref_url="http://linux.oracle.com/cve/CVE-2012-3499.html" source="CVE"/>
        <reference ref_id="CVE-2012-4558" ref_url="http://linux.oracle.com/cve/CVE-2012-4558.html" source="CVE"/>
        <reference ref_id="CVE-2013-1862" ref_url="http://linux.oracle.com/cve/CVE-2013-1862.html" source="CVE"/>
        <description>mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:48.693-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.180-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:51.812-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23465 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:34.157-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:28.231-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:37:37.370-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:37:37.370-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107162"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107327"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107298"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107488"/>
            <criterion comment="httpd is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:107390"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:107191"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:107478"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:107238"/>
            <criterion comment="httpd is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:107348"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23462" version="25" class="patch">
      <metadata>
        <title>ELSA-2013:0271: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>devhelp</product>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>yelp</product>
          <product>libproxy</product>
        </affected>
        <reference ref_id="ELSA-2013:0271-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0271.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0775" ref_url="http://linux.oracle.com/cve/CVE-2013-0775.html" source="CVE"/>
        <reference ref_id="CVE-2013-0776" ref_url="http://linux.oracle.com/cve/CVE-2013-0776.html" source="CVE"/>
        <reference ref_id="CVE-2013-0780" ref_url="http://linux.oracle.com/cve/CVE-2013-0780.html" source="CVE"/>
        <reference ref_id="CVE-2013-0782" ref_url="http://linux.oracle.com/cve/CVE-2013-0782.html" source="CVE"/>
        <reference ref_id="CVE-2013-0783" ref_url="http://linux.oracle.com/cve/CVE-2013-0783.html" source="CVE"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:42:27.894-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.839-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:51.321-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23462 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.442-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:27.811-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="yelp is earlier than 0:2.28.1-17.el6_3" test_ref="oval:org.mitre.oval:tst:111026"/>
            <criterion comment="libproxy-bin is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111368"/>
            <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111442"/>
            <criterion comment="libproxy-devel is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111437"/>
            <criterion comment="libproxy-webkit is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111307"/>
            <criterion comment="libproxy is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111462"/>
            <criterion comment="libproxy-gnome is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111353"/>
            <criterion comment="libproxy-python is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111506"/>
            <criterion comment="libproxy-kde is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:111299"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111385"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111515"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111045"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:111045"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="yelp is earlier than 0:2.16.0-30.el5_9" test_ref="oval:org.mitre.oval:tst:111189"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:111461"/>
            <criterion comment="devhelp is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:111469"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:111213"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:111160"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:111286"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23461" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0516: evolution security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>evolution</product>
        </affected>
        <reference ref_id="ELSA-2013:0516-02" ref_url="http://linux.oracle.com/errata/ELSA-2013-0516.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3201" ref_url="http://linux.oracle.com/cve/CVE-2011-3201.html" source="CVE"/>
        <description>GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:44:48.928-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.761-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:51.209-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23461 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.255-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:27.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="evolution is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:110742"/>
          <criterion comment="evolution-devel is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:111567"/>
          <criterion comment="evolution-conduits is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:111536"/>
          <criterion comment="evolution-perl is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:111370"/>
          <criterion comment="evolution-spamassassin is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:110784"/>
          <criterion comment="evolution-pst is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:110841"/>
          <criterion comment="evolution-help is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:110957"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23460" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0558: perl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference ref_id="ELSA-2011:0558-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0558.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-2761" ref_url="http://linux.oracle.com/cve/CVE-2010-2761.html" source="CVE"/>
        <reference ref_id="CVE-2010-4410" ref_url="http://linux.oracle.com/cve/CVE-2010-4410.html" source="CVE"/>
        <reference ref_id="CVE-2011-1487" ref_url="http://linux.oracle.com/cve/CVE-2011-1487.html" source="CVE"/>
        <description>The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:41.879-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.574-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:50.930-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23460 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.412-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:27.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="perl-libs is earlier than 4:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:108680"/>
          <criterion comment="perl-core is earlier than 0:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:108546"/>
          <criterion comment="perl-Package-Constants is earlier than 1:0.02-119.el6" test_ref="oval:org.mitre.oval:tst:108874"/>
          <criterion comment="perl-suidperl is earlier than 4:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:108838"/>
          <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-119.el6" test_ref="oval:org.mitre.oval:tst:108812"/>
          <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-119.el6" test_ref="oval:org.mitre.oval:tst:108918"/>
          <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-119.el6" test_ref="oval:org.mitre.oval:tst:108855"/>
          <criterion comment="perl-Archive-Extract is earlier than 1:0.38-119.el6" test_ref="oval:org.mitre.oval:tst:108370"/>
          <criterion comment="perl-CGI is earlier than 0:3.51-119.el6" test_ref="oval:org.mitre.oval:tst:108544"/>
          <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-119.el6" test_ref="oval:org.mitre.oval:tst:108899"/>
          <criterion comment="perl-version is earlier than 3:0.77-119.el6" test_ref="oval:org.mitre.oval:tst:108927"/>
          <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-119.el6" test_ref="oval:org.mitre.oval:tst:108797"/>
          <criterion comment="perl-Compress-Raw-Zlib is earlier than 0:2.023-119.el6" test_ref="oval:org.mitre.oval:tst:108645"/>
          <criterion comment="perl-Test-Simple is earlier than 0:0.92-119.el6" test_ref="oval:org.mitre.oval:tst:108221"/>
          <criterion comment="perl-Module-Loaded is earlier than 1:0.02-119.el6" test_ref="oval:org.mitre.oval:tst:108563"/>
          <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-119.el6" test_ref="oval:org.mitre.oval:tst:108646"/>
          <criterion comment="perl-CPANPLUS is earlier than 0:0.88-119.el6" test_ref="oval:org.mitre.oval:tst:108498"/>
          <criterion comment="perl-parent is earlier than 1:0.221-119.el6" test_ref="oval:org.mitre.oval:tst:108416"/>
          <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-119.el6" test_ref="oval:org.mitre.oval:tst:108365"/>
          <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-119.el6" test_ref="oval:org.mitre.oval:tst:108952"/>
          <criterion comment="perl-Test-Harness is earlier than 0:3.17-119.el6" test_ref="oval:org.mitre.oval:tst:108767"/>
          <criterion comment="perl-Pod-Simple is earlier than 1:3.13-119.el6" test_ref="oval:org.mitre.oval:tst:108960"/>
          <criterion comment="perl-Module-Load is earlier than 1:0.16-119.el6" test_ref="oval:org.mitre.oval:tst:108392"/>
          <criterion comment="perl-File-Fetch is earlier than 0:0.26-119.el6" test_ref="oval:org.mitre.oval:tst:108806"/>
          <criterion comment="perl-Module-CoreList is earlier than 0:2.18-119.el6" test_ref="oval:org.mitre.oval:tst:108926"/>
          <criterion comment="perl-IO-Zlib is earlier than 1:1.09-119.el6" test_ref="oval:org.mitre.oval:tst:108848"/>
          <criterion comment="perl-Params-Check is earlier than 1:0.26-119.el6" test_ref="oval:org.mitre.oval:tst:108830"/>
          <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-119.el6" test_ref="oval:org.mitre.oval:tst:108827"/>
          <criterion comment="perl is earlier than 4:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:108939"/>
          <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-119.el6" test_ref="oval:org.mitre.oval:tst:108922"/>
          <criterion comment="perl-devel is earlier than 4:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:108542"/>
          <criterion comment="perl-Time-Piece is earlier than 0:1.15-119.el6" test_ref="oval:org.mitre.oval:tst:108949"/>
          <criterion comment="perl-Digest-SHA is earlier than 1:5.47-119.el6" test_ref="oval:org.mitre.oval:tst:108784"/>
          <criterion comment="perl-Archive-Tar is earlier than 0:1.58-119.el6" test_ref="oval:org.mitre.oval:tst:108936"/>
          <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-119.el6" test_ref="oval:org.mitre.oval:tst:108462"/>
          <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-119.el6" test_ref="oval:org.mitre.oval:tst:108909"/>
          <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-119.el6" test_ref="oval:org.mitre.oval:tst:108374"/>
          <criterion comment="perl-CPAN is earlier than 0:1.9402-119.el6" test_ref="oval:org.mitre.oval:tst:108787"/>
          <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-119.el6" test_ref="oval:org.mitre.oval:tst:108817"/>
          <criterion comment="perl-Term-UI is earlier than 0:0.20-119.el6" test_ref="oval:org.mitre.oval:tst:108782"/>
          <criterion comment="perl-Object-Accessor is earlier than 1:0.34-119.el6" test_ref="oval:org.mitre.oval:tst:108914"/>
          <criterion comment="perl-Module-Build is earlier than 1:0.3500-119.el6" test_ref="oval:org.mitre.oval:tst:108763"/>
          <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-119.el6" test_ref="oval:org.mitre.oval:tst:108761"/>
          <criterion comment="perl-Log-Message is earlier than 1:0.02-119.el6" test_ref="oval:org.mitre.oval:tst:108521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23459" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0428: dhcp security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference ref_id="ELSA-2011:0428-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0428.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0997" ref_url="http://linux.oracle.com/cve/CVE-2011-0997.html" source="CVE"/>
        <description>dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:36.322-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.475-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:50.808-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23459 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.810-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:27.319-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:108783"/>
          <criterion comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:108796"/>
          <criterion comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:108537"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23457" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0324: logwatch security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>logwatch</product>
        </affected>
        <reference ref_id="ELSA-2011:0324-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0324.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1018" ref_url="http://linux.oracle.com/cve/CVE-2011-1018.html" source="CVE"/>
        <description>logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:21.889-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.313-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:50.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23457 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.313-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:27.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="logwatch is earlier than 0:7.3.6-49.el6" test_ref="oval:org.mitre.oval:tst:108608"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23455" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0165: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference ref_id="ELSA-2013:0165-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0165.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3174" ref_url="http://linux.oracle.com/cve/CVE-2012-3174.html" source="CVE"/>
        <reference ref_id="CVE-2013-0422" ref_url="http://linux.oracle.com/cve/CVE-2013-0422.html" source="CVE"/>
        <description>Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114.  CVE-2013-0422 covers both the JMX/MBean and Reflection API issues.  NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks.  NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11.  If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:26:58.148-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.076-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:50.254-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23455 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.164-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:26.946-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:36:41.160-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:36:41.160-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:106133"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:106901"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:106837"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:106874"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:107132"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:107113"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:107081"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:106714"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:106975"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:106820"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23454" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0423: postfix security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>postfix</product>
        </affected>
        <reference ref_id="ELSA-2011:0423-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0423.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0411" ref_url="http://linux.oracle.com/cve/CVE-2011-0411.html" source="CVE"/>
        <description>The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:27.781-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:10.014-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:50.157-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23454 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.508-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:26.850-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="postfix-perl-scripts is earlier than 2:2.6.6-2.1.el6_0" test_ref="oval:org.mitre.oval:tst:108773"/>
          <criterion comment="postfix is earlier than 2:2.6.6-2.1.el6_0" test_ref="oval:org.mitre.oval:tst:108415"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23453" version="97" class="patch">
      <metadata>
        <title>ELSA-2010:0987: java-1.6.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2010:0987-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0987.html" source="VENDOR"/>
        <reference ref_id="CVE-2009-3555" ref_url="http://linux.oracle.com/cve/CVE-2009-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-1321" ref_url="http://linux.oracle.com/cve/CVE-2010-1321.html" source="CVE"/>
        <reference ref_id="CVE-2010-3541" ref_url="http://linux.oracle.com/cve/CVE-2010-3541.html" source="CVE"/>
        <reference ref_id="CVE-2010-3548" ref_url="http://linux.oracle.com/cve/CVE-2010-3548.html" source="CVE"/>
        <reference ref_id="CVE-2010-3549" ref_url="http://linux.oracle.com/cve/CVE-2010-3549.html" source="CVE"/>
        <reference ref_id="CVE-2010-3550" ref_url="http://linux.oracle.com/cve/CVE-2010-3550.html" source="CVE"/>
        <reference ref_id="CVE-2010-3551" ref_url="http://linux.oracle.com/cve/CVE-2010-3551.html" source="CVE"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3555" ref_url="http://linux.oracle.com/cve/CVE-2010-3555.html" source="CVE"/>
        <reference ref_id="CVE-2010-3556" ref_url="http://linux.oracle.com/cve/CVE-2010-3556.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3558" ref_url="http://linux.oracle.com/cve/CVE-2010-3558.html" source="CVE"/>
        <reference ref_id="CVE-2010-3560" ref_url="http://linux.oracle.com/cve/CVE-2010-3560.html" source="CVE"/>
        <reference ref_id="CVE-2010-3562" ref_url="http://linux.oracle.com/cve/CVE-2010-3562.html" source="CVE"/>
        <reference ref_id="CVE-2010-3563" ref_url="http://linux.oracle.com/cve/CVE-2010-3563.html" source="CVE"/>
        <reference ref_id="CVE-2010-3565" ref_url="http://linux.oracle.com/cve/CVE-2010-3565.html" source="CVE"/>
        <reference ref_id="CVE-2010-3566" ref_url="http://linux.oracle.com/cve/CVE-2010-3566.html" source="CVE"/>
        <reference ref_id="CVE-2010-3568" ref_url="http://linux.oracle.com/cve/CVE-2010-3568.html" source="CVE"/>
        <reference ref_id="CVE-2010-3569" ref_url="http://linux.oracle.com/cve/CVE-2010-3569.html" source="CVE"/>
        <reference ref_id="CVE-2010-3571" ref_url="http://linux.oracle.com/cve/CVE-2010-3571.html" source="CVE"/>
        <reference ref_id="CVE-2010-3572" ref_url="http://linux.oracle.com/cve/CVE-2010-3572.html" source="CVE"/>
        <reference ref_id="CVE-2010-3573" ref_url="http://linux.oracle.com/cve/CVE-2010-3573.html" source="CVE"/>
        <reference ref_id="CVE-2010-3574" ref_url="http://linux.oracle.com/cve/CVE-2010-3574.html" source="CVE"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:38.892-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:09.501-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:49.334-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23453 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.964-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:26.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107995"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107481"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:108007"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107919"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107928"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:107837"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:108148"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:108209"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:108206"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:108253"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107963"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107913"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107577"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107909"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:107818"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23452" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0132: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2014:0132-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0132.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1477" ref_url="http://linux.oracle.com/cve/CVE-2014-1477.html" source="CVE"/>
        <reference ref_id="CVE-2014-1479" ref_url="http://linux.oracle.com/cve/CVE-2014-1479.html" source="CVE"/>
        <reference ref_id="CVE-2014-1481" ref_url="http://linux.oracle.com/cve/CVE-2014-1481.html" source="CVE"/>
        <reference ref_id="CVE-2014-1482" ref_url="http://linux.oracle.com/cve/CVE-2014-1482.html" source="CVE"/>
        <reference ref_id="CVE-2014-1486" ref_url="http://linux.oracle.com/cve/CVE-2014-1486.html" source="CVE"/>
        <reference ref_id="CVE-2014-1487" ref_url="http://linux.oracle.com/cve/CVE-2014-1487.html" source="CVE"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:08.781-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:09.325-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:49.052-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23452 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.601-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:26.111-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:35:44.520-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:35:44.520-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:107996"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:107462"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23450" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1267: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1267-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1267.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
The RHSA-2011:1243 Thunderbird update rendered HTTPS certificates signed by
a certain Certificate Authority (CA) as untrusted, but made an exception
for a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)
All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:18.754-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:09.173-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.829-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23450 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.802-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-25.el5" test_ref="oval:org.mitre.oval:tst:109275"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:3.1.14-1.el6_1" test_ref="oval:org.mitre.oval:tst:109185"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23449" version="6" class="patch">
      <metadata>
        <title>ELSA-2013:0581: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2013:0581-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0581.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0338" ref_url="http://linux.oracle.com/cve/CVE-2013-0338.html" source="CVE"/>
        <description>libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:05.824-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:09.090-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.659-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23449 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.717-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:106789"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:106852"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:107174"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:106236"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:106862"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:107226"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:107203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23448" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:0169: java-1.5.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0169-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0169.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3553" ref_url="http://linux.oracle.com/cve/CVE-2010-3553.html" source="CVE"/>
        <reference ref_id="CVE-2010-3557" ref_url="http://linux.oracle.com/cve/CVE-2010-3557.html" source="CVE"/>
        <reference ref_id="CVE-2010-3571" ref_url="http://linux.oracle.com/cve/CVE-2010-3571.html" source="CVE"/>
        <description>Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the color profile parser that allows remote attackers to execute arbitrary code via a crafted Tag structure in a color profile.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:24.957-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.934-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.455-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23448 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.749-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108333"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108315"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:107451"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108119"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108196"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108353"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:107654"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:108423"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:107575"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108296"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108258"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108385"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108438"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108347"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:108348"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23446" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0883: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference ref_id="ELSA-2013:0883-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0883.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-2116" ref_url="http://linux.oracle.com/cve/CVE-2013-2116.html" source="CVE"/>
        <description>The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length.  NOTE: this might be due to an incorrect fix for CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:46:38.199-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.861-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.317-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23446 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.139-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.437-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:35:12.547-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:35:12.547-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:112092"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:112106"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111406"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:111897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:111537"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:111145"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:111639"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23444" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1457: libgcrypt security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libgcrypt</product>
        </affected>
        <reference ref_id="ELSA-2013:1457-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1457.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4242" ref_url="http://linux.oracle.com/cve/CVE-2013-4242.html" source="CVE"/>
        <description>GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:33.974-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.741-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.144-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23444 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:28.685-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.251-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:34:23.298-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:34:23.298-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:107763"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:107602"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:107403"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:107646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23443" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:0600: dovecot security and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference ref_id="ELSA-2011:0600-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0600.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3707" ref_url="http://linux.oracle.com/cve/CVE-2010-3707.html" source="CVE"/>
        <reference ref_id="CVE-2010-3780" ref_url="http://linux.oracle.com/cve/CVE-2010-3780.html" source="CVE"/>
        <description>Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:32.948-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.650-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:48.004-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23443 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.226-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:108951"/>
          <criterion comment="dovecot-mysql is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:108974"/>
          <criterion comment="dovecot is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:108756"/>
          <criterion comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:108505"/>
          <criterion comment="dovecot-devel is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:108890"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23442" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0356: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2011:0356-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0356.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0284" ref_url="http://linux.oracle.com/cve/CVE-2011-0284.html" source="CVE"/>
        <description>Double free vulnerability in the prepare_error_as function in do_as_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 through 1.9, when the PKINIT feature is enabled, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an e_data field containing typed data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:34.675-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.570-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:47.896-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23442 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.873-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:25.033-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:108520"/>
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:108458"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:108558"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:108658"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:108685"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:108662"/>
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:108616"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23440" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0975: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2010:0975-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0975.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3613" ref_url="http://linux.oracle.com/cve/CVE-2010-3613.html" source="CVE"/>
        <reference ref_id="CVE-2010-3614" ref_url="http://linux.oracle.com/cve/CVE-2010-3614.html" source="CVE"/>
        <description>named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:32.413-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.435-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:47.663-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23440 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.123-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:24.903-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108251"/>
          <criterion comment="bind-chroot is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108048"/>
          <criterion comment="bind-sdb is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108161"/>
          <criterion comment="bind-libs is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:108191"/>
          <criterion comment="bind-devel is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:107664"/>
          <criterion comment="bind-utils is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:107846"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23439" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1512: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference ref_id="ELSA-2012:1512-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1512.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5134" ref_url="http://linux.oracle.com/cve/CVE-2012-5134.html" source="CVE"/>
        <description>Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:44.018-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.364-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:47.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23439 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.552-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:24.787-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:33:45.085-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:33:45.085-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:107021"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:106930"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:106793"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:106915"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:106880"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:106227"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:106863"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23438" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1508: cyrus-imapd security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference ref_id="ELSA-2011:1508-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1508.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3372" ref_url="http://linux.oracle.com/cve/CVE-2011-3372.html" source="CVE"/>
        <reference ref_id="CVE-2011-3481" ref_url="http://linux.oracle.com/cve/CVE-2011-3481.html" source="CVE"/>
        <description>The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:05.508-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:08.270-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:47.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23438 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:30.432-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:24.612-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:108804"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:109228"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:109631"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:108887"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:109633"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:109471"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:109462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23437" version="65" class="patch">
      <metadata>
        <title>ELSA-2012:1465: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2012:1465-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1465.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1531" ref_url="http://linux.oracle.com/cve/CVE-2012-1531.html" source="CVE"/>
        <reference ref_id="CVE-2012-3143" ref_url="http://linux.oracle.com/cve/CVE-2012-3143.html" source="CVE"/>
        <reference ref_id="CVE-2012-3216" ref_url="http://linux.oracle.com/cve/CVE-2012-3216.html" source="CVE"/>
        <reference ref_id="CVE-2012-4820" ref_url="http://linux.oracle.com/cve/CVE-2012-4820.html" source="CVE"/>
        <reference ref_id="CVE-2012-4822" ref_url="http://linux.oracle.com/cve/CVE-2012-4822.html" source="CVE"/>
        <reference ref_id="CVE-2012-5069" ref_url="http://linux.oracle.com/cve/CVE-2012-5069.html" source="CVE"/>
        <reference ref_id="CVE-2012-5071" ref_url="http://linux.oracle.com/cve/CVE-2012-5071.html" source="CVE"/>
        <reference ref_id="CVE-2012-5073" ref_url="http://linux.oracle.com/cve/CVE-2012-5073.html" source="CVE"/>
        <reference ref_id="CVE-2012-5075" ref_url="http://linux.oracle.com/cve/CVE-2012-5075.html" source="CVE"/>
        <reference ref_id="CVE-2012-5079" ref_url="http://linux.oracle.com/cve/CVE-2012-5079.html" source="CVE"/>
        <reference ref_id="CVE-2012-5081" ref_url="http://linux.oracle.com/cve/CVE-2012-5081.html" source="CVE"/>
        <reference ref_id="CVE-2012-5083" ref_url="http://linux.oracle.com/cve/CVE-2012-5083.html" source="CVE"/>
        <reference ref_id="CVE-2012-5084" ref_url="http://linux.oracle.com/cve/CVE-2012-5084.html" source="CVE"/>
        <reference ref_id="CVE-2012-5089" ref_url="http://linux.oracle.com/cve/CVE-2012-5089.html" source="CVE"/>
        <reference ref_id="CVE-2013-1475" ref_url="http://linux.oracle.com/cve/CVE-2013-1475.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.java.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:02.919-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:07.930-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:46.734-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23437 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.270-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:24.215-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110450"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111180"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110960"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111103"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:111237"/>
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110690"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:110677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23434" version="38" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1476: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:1476-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1476.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-5590" ref_url="http://linux.oracle.com/cve/CVE-2013-5590.html" source="CVE"/>
        <reference ref_id="CVE-2013-5595" ref_url="http://linux.oracle.com/cve/CVE-2013-5595.html" source="CVE"/>
        <reference ref_id="CVE-2013-5597" ref_url="http://linux.oracle.com/cve/CVE-2013-5597.html" source="CVE"/>
        <reference ref_id="CVE-2013-5599" ref_url="http://linux.oracle.com/cve/CVE-2013-5599.html" source="CVE"/>
        <reference ref_id="CVE-2013-5600" ref_url="http://linux.oracle.com/cve/CVE-2013-5600.html" source="CVE"/>
        <reference ref_id="CVE-2013-5601" ref_url="http://linux.oracle.com/cve/CVE-2013-5601.html" source="CVE"/>
        <reference ref_id="CVE-2013-5602" ref_url="http://linux.oracle.com/cve/CVE-2013-5602.html" source="CVE"/>
        <reference ref_id="CVE-2013-5604" ref_url="http://linux.oracle.com/cve/CVE-2013-5604.html" source="CVE"/>
        <description>The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via crafted documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:25.244-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:07.402-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:45.839-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23434 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:28.580-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:23.471-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:32:56.652-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:32:56.652-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:107830"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:107236"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:107321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:107482"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:107485"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:107652"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23433" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0774: libguestfs security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libguestfs</product>
        </affected>
        <reference ref_id="ELSA-2012:0774-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0774.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2690" ref_url="http://linux.oracle.com/cve/CVE-2012-2690.html" source="CVE"/>
        <description>virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:36.602-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:07.319-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:45.713-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23433 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.773-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:23.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libguestfs-javadoc is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:109893"/>
          <criterion comment="libguestfs-java-devel is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:110523"/>
          <criterion comment="libguestfs-java is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:110175"/>
          <criterion comment="perl-Sys-Guestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:110533"/>
          <criterion comment="libguestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:110497"/>
          <criterion comment="ocaml-libguestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:110508"/>
          <criterion comment="python-libguestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:110275"/>
          <criterion comment="ocaml-libguestfs-devel is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:109803"/>
          <criterion comment="libguestfs-devel is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:109895"/>
          <criterion comment="libguestfs-tools-c is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:110180"/>
          <criterion comment="ruby-libguestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:110113"/>
          <criterion comment="libguestfs-tools is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:109826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23432" version="5" class="patch">
      <metadata>
        <title>ELSA-2011:1248: ca-certificates security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ca-certificates</product>
        </affected>
        <reference ref_id="ELSA-2011:1248-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1248.html" source="VENDOR"/>
        <description>This package contains the set of CA certificates chosen by the Mozilla
Foundation for use with the Internet Public Key Infrastructure (PKI).
It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update removes that CA's root certificate from the
ca-certificates package, rendering any HTTPS certificates signed by that CA
as untrusted. (BZ#734381)
All users should upgrade to this updated package. After installing the
update, all applications using the ca-certificates package must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:13.498-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:07.278-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:45.655-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23432 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.647-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:23.266-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="ca-certificates is earlier than 0:2010.63-3.el6_1.5" test_ref="oval:org.mitre.oval:tst:109231"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23431" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0902: cifs-utils security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>cifs-utils</product>
        </affected>
        <reference ref_id="ELSA-2012:0902-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0902.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1586" ref_url="http://linux.oracle.com/cve/CVE-2012-1586.html" source="CVE"/>
        <description>mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:22.297-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:07.215-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:45.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23431 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.049-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:23.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="cifs-utils is earlier than 0:4.8.1-10.el6" test_ref="oval:org.mitre.oval:tst:110499"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23429" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0465: kdenetwork security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kdenetwork</product>
        </affected>
        <reference ref_id="ELSA-2011:0465-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0465.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1586" ref_url="http://linux.oracle.com/cve/CVE-2011-1586.html" source="CVE"/>
        <description>Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:38.085-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.995-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:45.366-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23429 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:32.012-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:22.960-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kdenetwork-libs is earlier than 7:4.3.4-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:108050"/>
          <criterion comment="kdenetwork-devel is earlier than 7:4.3.4-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:107936"/>
          <criterion comment="kdenetwork is earlier than 7:4.3.4-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:108678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23428" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0871: tigervnc security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>tigervnc</product>
        </affected>
        <reference ref_id="ELSA-2011:0871-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0871.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1775" ref_url="http://linux.oracle.com/cve/CVE-2011-1775.html" source="CVE"/>
        <description>The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:09.206-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.919-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:45.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23428 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:29.969-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:22.818-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="tigervnc-server-module is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:109054"/>
          <criterion comment="tigervnc is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:108651"/>
          <criterion comment="tigervnc-server is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:108959"/>
          <criterion comment="tigervnc-server-applet is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:108856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23427" version="29" class="patch">
      <metadata>
        <title>ELSA-2011:1241: ecryptfs-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ecryptfs-utils</product>
        </affected>
        <reference ref_id="ELSA-2011:1241-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1241.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1831" ref_url="http://linux.oracle.com/cve/CVE-2011-1831.html" source="CVE"/>
        <reference ref_id="CVE-2011-1832" ref_url="http://linux.oracle.com/cve/CVE-2011-1832.html" source="CVE"/>
        <reference ref_id="CVE-2011-1834" ref_url="http://linux.oracle.com/cve/CVE-2011-1834.html" source="CVE"/>
        <reference ref_id="CVE-2011-1835" ref_url="http://linux.oracle.com/cve/CVE-2011-1835.html" source="CVE"/>
        <reference ref_id="CVE-2011-1837" ref_url="http://linux.oracle.com/cve/CVE-2011-1837.html" source="CVE"/>
        <reference ref_id="CVE-2011-3145" ref_url="http://linux.oracle.com/cve/CVE-2011-3145.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:19.100-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.725-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:44.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23427 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:31.404-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:22.542-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:109224"/>
            <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:108858"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:109267"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109232"/>
            <criterion comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109063"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:109203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23426" version="13" class="patch">
      <metadata>
        <title>ELSA-2013:1436: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2013:1436-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1436.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4162" ref_url="http://linux.oracle.com/cve/CVE-2013-4162.html" source="CVE"/>
        <reference ref_id="CVE-2013-4299" ref_url="http://linux.oracle.com/cve/CVE-2013-4299.html" source="CVE"/>
        <description>Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:51:05.309-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.607-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:44.754-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23426 - optimisation of Oracle Linux content" date="2014-05-05T17:37:00.448-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:41:33.151-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:22.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:112409"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:111986"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:112477"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:112143"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:112350"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:111503"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:112274"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:112291"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:111635"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:111764"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:112458"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:112457"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23424" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1507: libarchive security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>libarchive</product>
        </affected>
        <reference ref_id="ELSA-2011:1507-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1507.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1777" ref_url="http://linux.oracle.com/cve/CVE-2011-1777.html" source="CVE"/>
        <reference ref_id="CVE-2011-1778" ref_url="http://linux.oracle.com/cve/CVE-2011-1778.html" source="CVE"/>
        <description>Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:52.507-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.414-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:44.437-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23424 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:31.478-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:56.833-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="libarchive-devel is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:109429"/>
          <criterion comment="libarchive is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:109488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23423" version="6" class="patch">
      <metadata>
        <title>ELSA-2010:0863: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference ref_id="ELSA-2010:0863-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0863.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-1322" ref_url="http://linux.oracle.com/cve/CVE-2010-1322.html" source="CVE"/>
        <description>The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of service (daemon crash), or possibly obtain sensitive information, spoof authorization, or execute arbitrary code, via a TGS request that triggers an uninitialized pointer dereference, as demonstrated by a request from a Windows Active Directory client.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:35.947-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.331-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:44.325-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23423 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.360-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:22.105-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108124"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107824"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107672"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107820"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:107895"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108096"/>
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:108073"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23422" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0811: php-pecl-apc security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>php-pecl-apc</product>
        </affected>
        <reference ref_id="ELSA-2012:0811-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0811.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3294" ref_url="http://linux.oracle.com/cve/CVE-2010-3294.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in apc.php in the Alternative PHP Cache (APC) extension before 3.1.4 for PHP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:19.436-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:06.255-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:44.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23422 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.904-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:21.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="php-pecl-apc is earlier than 0:3.1.9-2.el6" test_ref="oval:org.mitre.oval:tst:109584"/>
          <criterion comment="php-pecl-apc-devel is earlier than 0:3.1.9-2.el6" test_ref="oval:org.mitre.oval:tst:110117"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23419" version="22" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0685: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference ref_id="ELSA-2013:0685-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0685.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5195" ref_url="http://linux.oracle.com/cve/CVE-2012-5195.html" source="CVE"/>
        <reference ref_id="CVE-2012-5526" ref_url="http://linux.oracle.com/cve/CVE-2012-5526.html" source="CVE"/>
        <reference ref_id="CVE-2012-6329" ref_url="http://linux.oracle.com/cve/CVE-2012-6329.html" source="CVE"/>
        <reference ref_id="CVE-2013-1667" ref_url="http://linux.oracle.com/cve/CVE-2013-1667.html" source="CVE"/>
        <description>The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:59.140-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.769-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:43.535-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23419 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.237-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:21.476-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:32:11.461-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:32:11.461-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="perl-libs is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107323"/>
            <criterion comment="perl-suidperl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107355"/>
            <criterion comment="perl-core is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107266"/>
            <criterion comment="perl-Package-Constants is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:107224"/>
            <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-130.el6_4" test_ref="oval:org.mitre.oval:tst:107291"/>
            <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:107328"/>
            <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-130.el6_4" test_ref="oval:org.mitre.oval:tst:107324"/>
            <criterion comment="perl-CGI is earlier than 0:3.51-130.el6_4" test_ref="oval:org.mitre.oval:tst:107159"/>
            <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:107206"/>
            <criterion comment="perl-Archive-Extract is earlier than 1:0.38-130.el6_4" test_ref="oval:org.mitre.oval:tst:107329"/>
            <criterion comment="perl-version is earlier than 3:0.77-130.el6_4" test_ref="oval:org.mitre.oval:tst:106922"/>
            <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-130.el6_4" test_ref="oval:org.mitre.oval:tst:107171"/>
            <criterion comment="perl-Test-Simple is earlier than 0:0.92-130.el6_4" test_ref="oval:org.mitre.oval:tst:106790"/>
            <criterion comment="perl-Compress-Raw-Zlib is earlier than 1:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:106926"/>
            <criterion comment="perl-Module-Loaded is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:107247"/>
            <criterion comment="perl-IO-Compress-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:107244"/>
            <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-130.el6_4" test_ref="oval:org.mitre.oval:tst:107460"/>
            <criterion comment="perl-Test-Harness is earlier than 0:3.17-130.el6_4" test_ref="oval:org.mitre.oval:tst:107295"/>
            <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:107290"/>
            <criterion comment="perl-parent is earlier than 1:0.221-130.el6_4" test_ref="oval:org.mitre.oval:tst:107225"/>
            <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:107222"/>
            <criterion comment="perl-CPANPLUS is earlier than 0:0.88-130.el6_4" test_ref="oval:org.mitre.oval:tst:107110"/>
            <criterion comment="perl-Pod-Simple is earlier than 1:3.13-130.el6_4" test_ref="oval:org.mitre.oval:tst:107079"/>
            <criterion comment="perl-Module-Load is earlier than 1:0.16-130.el6_4" test_ref="oval:org.mitre.oval:tst:107030"/>
            <criterion comment="perl-File-Fetch is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:107271"/>
            <criterion comment="perl-Module-CoreList is earlier than 0:2.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:106971"/>
            <criterion comment="perl-IO-Zlib is earlier than 1:1.09-130.el6_4" test_ref="oval:org.mitre.oval:tst:106723"/>
            <criterion comment="perl-Params-Check is earlier than 1:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:106891"/>
            <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:106840"/>
            <criterion comment="perl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107346"/>
            <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-130.el6_4" test_ref="oval:org.mitre.oval:tst:107442"/>
            <criterion comment="perl-Digest-SHA is earlier than 1:5.47-130.el6_4" test_ref="oval:org.mitre.oval:tst:107377"/>
            <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:107349"/>
            <criterion comment="perl-Time-Piece is earlier than 0:1.15-130.el6_4" test_ref="oval:org.mitre.oval:tst:106954"/>
            <criterion comment="perl-Archive-Tar is earlier than 0:1.58-130.el6_4" test_ref="oval:org.mitre.oval:tst:107319"/>
            <criterion comment="perl-devel is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:107366"/>
            <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-130.el6_4" test_ref="oval:org.mitre.oval:tst:107331"/>
            <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-130.el6_4" test_ref="oval:org.mitre.oval:tst:106492"/>
            <criterion comment="perl-Module-Build is earlier than 1:0.3500-130.el6_4" test_ref="oval:org.mitre.oval:tst:107340"/>
            <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-130.el6_4" test_ref="oval:org.mitre.oval:tst:107371"/>
            <criterion comment="perl-CPAN is earlier than 0:1.9402-130.el6_4" test_ref="oval:org.mitre.oval:tst:106903"/>
            <criterion comment="perl-Term-UI is earlier than 0:0.20-130.el6_4" test_ref="oval:org.mitre.oval:tst:107257"/>
            <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-130.el6_4" test_ref="oval:org.mitre.oval:tst:107250"/>
            <criterion comment="perl-Object-Accessor is earlier than 1:0.34-130.el6_4" test_ref="oval:org.mitre.oval:tst:107059"/>
            <criterion comment="perl-Compress-Raw-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:106834"/>
            <criterion comment="perl-Log-Message is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:106906"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="perl-suidperl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:107333"/>
            <criterion comment="perl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:107489"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23416" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0677: openssl security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2011:0677-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0677.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0014" ref_url="http://linux.oracle.com/cve/CVE-2011-0014.html" source="CVE"/>
        <description>ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:33.783-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.513-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:43.116-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23416 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.871-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:21.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl-devel is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:108519"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:108968"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:108698"/>
          <criterion comment="openssl is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:108891"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23413" version="34" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1087: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:1087-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1087.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0802" ref_url="http://linux.oracle.com/cve/CVE-2011-0802.html" source="CVE"/>
        <reference ref_id="CVE-2011-0814" ref_url="http://linux.oracle.com/cve/CVE-2011-0814.html" source="CVE"/>
        <reference ref_id="CVE-2011-0862" ref_url="http://linux.oracle.com/cve/CVE-2011-0862.html" source="CVE"/>
        <reference ref_id="CVE-2011-0865" ref_url="http://linux.oracle.com/cve/CVE-2011-0865.html" source="CVE"/>
        <reference ref_id="CVE-2011-0867" ref_url="http://linux.oracle.com/cve/CVE-2011-0867.html" source="CVE"/>
        <reference ref_id="CVE-2011-0871" ref_url="http://linux.oracle.com/cve/CVE-2011-0871.html" source="CVE"/>
        <reference ref_id="CVE-2011-0873" ref_url="http://linux.oracle.com/cve/CVE-2011-0873.html" source="CVE"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:21.080-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:05.148-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:42.500-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23413 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.597-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:20.574-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:28:32.764-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:28:32.764-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104784"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105154"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104813"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104589"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104776"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104970"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:105143"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:104831"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104990"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104703"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105110"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104729"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105133"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:104577"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:105038"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23411" version="57" class="patch">
      <metadata>
        <title>ELSA-2011:0885: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2011:0885-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0885.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0083" ref_url="http://linux.oracle.com/cve/CVE-2011-0083.html" source="CVE"/>
        <reference ref_id="CVE-2011-0085" ref_url="http://linux.oracle.com/cve/CVE-2011-0085.html" source="CVE"/>
        <reference ref_id="CVE-2011-2362" ref_url="http://linux.oracle.com/cve/CVE-2011-2362.html" source="CVE"/>
        <reference ref_id="CVE-2011-2363" ref_url="http://linux.oracle.com/cve/CVE-2011-2363.html" source="CVE"/>
        <reference ref_id="CVE-2011-2364" ref_url="http://linux.oracle.com/cve/CVE-2011-2364.html" source="CVE"/>
        <reference ref_id="CVE-2011-2365" ref_url="http://linux.oracle.com/cve/CVE-2011-2365.html" source="CVE"/>
        <reference ref_id="CVE-2011-2371" ref_url="http://linux.oracle.com/cve/CVE-2011-2371.html" source="CVE"/>
        <reference ref_id="CVE-2011-2373" ref_url="http://linux.oracle.com/cve/CVE-2011-2373.html" source="CVE"/>
        <reference ref_id="CVE-2011-2374" ref_url="http://linux.oracle.com/cve/CVE-2011-2374.html" source="CVE"/>
        <reference ref_id="CVE-2011-2375" ref_url="http://linux.oracle.com/cve/CVE-2011-2375.html" source="CVE"/>
        <reference ref_id="CVE-2011-2376" ref_url="http://linux.oracle.com/cve/CVE-2011-2376.html" source="CVE"/>
        <reference ref_id="CVE-2011-2377" ref_url="http://linux.oracle.com/cve/CVE-2011-2377.html" source="CVE"/>
        <reference ref_id="CVE-2011-2605" ref_url="http://linux.oracle.com/cve/CVE-2011-2605.html" source="CVE"/>
        <description>CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:22.890-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.774-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:41.845-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23411 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.703-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:20.108-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="firefox is earlier than 0:3.6.18-1.el6_1" test_ref="oval:org.mitre.oval:tst:109098"/>
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.18-2.el6_1" test_ref="oval:org.mitre.oval:tst:109093"/>
          <criterion comment="xulrunner is earlier than 0:1.9.2.18-2.el6_1" test_ref="oval:org.mitre.oval:tst:108869"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23410" version="17" class="patch">
      <metadata>
        <title>ELSA-2011:1439: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1439-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1439.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3647" ref_url="http://linux.oracle.com/cve/CVE-2011-3647.html" source="CVE"/>
        <reference ref_id="CVE-2011-3648" ref_url="http://linux.oracle.com/cve/CVE-2011-3648.html" source="CVE"/>
        <reference ref_id="CVE-2011-3650" ref_url="http://linux.oracle.com/cve/CVE-2011-3650.html" source="CVE"/>
        <description>Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:14.804-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.679-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:41.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23410 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.477-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:19.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.16-2.el6_1" test_ref="oval:org.mitre.oval:tst:109487"/>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23409" version="17" class="patch">
      <metadata>
        <title>ELSA-2012:1407: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2012:1407-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1407.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4194" ref_url="http://linux.oracle.com/cve/CVE-2012-4194.html" source="CVE"/>
        <reference ref_id="CVE-2012-4195" ref_url="http://linux.oracle.com/cve/CVE-2012-4195.html" source="CVE"/>
        <reference ref_id="CVE-2012-4196" ref_url="http://linux.oracle.com/cve/CVE-2012-4196.html" source="CVE"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:40:14.233-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.568-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:41.489-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23409 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.063-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:19.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:111234"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:110808"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:111259"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:110878"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:111226"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:110664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23407" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0716: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2012:0716-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0716.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1033" ref_url="http://linux.oracle.com/cve/CVE-2012-1033.html" source="CVE"/>
        <reference ref_id="CVE-2012-1667" ref_url="http://linux.oracle.com/cve/CVE-2012-1667.html" source="CVE"/>
        <description>ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:05.094-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.342-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:41.137-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23407 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:10.993-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:19.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106310"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:105987"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106493"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106287"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106586"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106063"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106623"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:106397"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106572"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106100"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:105993"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106194"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106494"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:106552"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23406" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0290: java-1.6.0-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference ref_id="ELSA-2011:0290-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0290.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4476" ref_url="http://linux.oracle.com/cve/CVE-2010-4476.html" source="CVE"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:33.860-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.230-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.991-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23406 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.821-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:19.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108634"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108555"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108524"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108557"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108375"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:108267"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:107666"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:107737"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108371"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108352"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108642"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:107892"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108590"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108513"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:108553"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23405" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0309: pango security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>pango</product>
        </affected>
        <reference ref_id="ELSA-2011:0309-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0309.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0064" ref_url="http://linux.oracle.com/cve/CVE-2011-0064.html" source="CVE"/>
        <description>The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:23:24.366-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.159-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.887-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23405 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:16.338-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="pango is earlier than 0:1.28.1-3.el6_0.5" test_ref="oval:org.mitre.oval:tst:108631"/>
          <criterion comment="pango-devel is earlier than 0:1.28.1-3.el6_0.5" test_ref="oval:org.mitre.oval:tst:108483"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23404" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1154: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference ref_id="ELSA-2011:1154-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1154.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2895" ref_url="http://linux.oracle.com/cve/CVE-2011-2895.html" source="CVE"/>
        <description>The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:14.663-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:04.081-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.784-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23404 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.913-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.861-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:109223"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:109314"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libXfont is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:109209"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:108474"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23400" version="13" class="patch">
      <metadata>
        <title>ELSA-2012:0810: busybox security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>busybox</product>
        </affected>
        <reference ref_id="ELSA-2012:0810-04" ref_url="http://linux.oracle.com/errata/ELSA-2012-0810.html" source="VENDOR"/>
        <reference ref_id="CVE-2006-1168" ref_url="http://linux.oracle.com/cve/CVE-2006-1168.html" source="CVE"/>
        <reference ref_id="CVE-2011-2716" ref_url="http://linux.oracle.com/cve/CVE-2011-2716.html" source="CVE"/>
        <description>The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:35:32.882-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.648-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.237-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23400 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.718-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="busybox-petitboot is earlier than 1:1.15.1-15.el6" test_ref="oval:org.mitre.oval:tst:110563"/>
          <criterion comment="busybox is earlier than 1:1.15.1-15.el6" test_ref="oval:org.mitre.oval:tst:110359"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23399" version="6" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1243: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2011:1243-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1243.html" source="VENDOR"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.
It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Thunderbird; however, affected certificates
issued after this date cannot be re-enabled or used. (BZ#734316)
All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:25.087-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.590-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:40.169-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23399 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.056-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.291-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:27:19.368-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:27:19.368-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-24.el5" test_ref="oval:org.mitre.oval:tst:105138"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:3.1.12-2.el6_1" test_ref="oval:org.mitre.oval:tst:105134"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23398" version="18" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1778: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference ref_id="ELSA-2013:1778-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1778.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-5576" ref_url="http://linux.oracle.com/cve/CVE-2012-5576.html" source="CVE"/>
        <reference ref_id="CVE-2013-1913" ref_url="http://linux.oracle.com/cve/CVE-2013-1913.html" source="CVE"/>
        <reference ref_id="CVE-2013-1978" ref_url="http://linux.oracle.com/cve/CVE-2013-1978.html" source="CVE"/>
        <description>Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:41.619-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.467-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:39.972-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23398 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.859-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.144-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:26:48.783-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:26:48.783-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gimp-libs is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:107792"/>
            <criterion comment="gimp-devel is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:107626"/>
            <criterion comment="gimp is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:107704"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="gimp-libs is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:107109"/>
            <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:106866"/>
            <criterion comment="gimp-devel is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:106876"/>
            <criterion comment="gimp is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:107579"/>
            <criterion comment="gimp-help-browser is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:107691"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23397" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1458: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2011:1458-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1458.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4313" ref_url="http://linux.oracle.com/cve/CVE-2011-4313.html" source="CVE"/>
        <description>query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:38.231-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.380-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:39.828-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23397 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.273-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:18.003-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:25:55.610-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:25:55.610-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105159"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105433"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105379"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105413"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105504"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105489"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105550"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:105516"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105452"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105228"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105481"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105025"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:104636"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:105214"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23396" version="38" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1812: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>firefox</product>
        </affected>
        <reference ref_id="ELSA-2013:1812-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-1812.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-0772" ref_url="http://linux.oracle.com/cve/CVE-2013-0772.html" source="CVE"/>
        <reference ref_id="CVE-2013-5609" ref_url="http://linux.oracle.com/cve/CVE-2013-5609.html" source="CVE"/>
        <reference ref_id="CVE-2013-5612" ref_url="http://linux.oracle.com/cve/CVE-2013-5612.html" source="CVE"/>
        <reference ref_id="CVE-2013-5613" ref_url="http://linux.oracle.com/cve/CVE-2013-5613.html" source="CVE"/>
        <reference ref_id="CVE-2013-5614" ref_url="http://linux.oracle.com/cve/CVE-2013-5614.html" source="CVE"/>
        <reference ref_id="CVE-2013-5616" ref_url="http://linux.oracle.com/cve/CVE-2013-5616.html" source="CVE"/>
        <reference ref_id="CVE-2013-5618" ref_url="http://linux.oracle.com/cve/CVE-2013-5618.html" source="CVE"/>
        <reference ref_id="CVE-2013-6671" ref_url="http://linux.oracle.com/cve/CVE-2013-6671.html" source="CVE"/>
        <description>The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:32:41.282-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:03.173-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:39.431-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23396 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:16.500-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:17.770-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:24:45.507-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:24:45.507-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:107902"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="firefox is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:107396"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23394" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:0845: bind security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>bind97</product>
          <product>bind</product>
        </affected>
        <reference ref_id="ELSA-2011:0845-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0845.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1910" ref_url="http://linux.oracle.com/cve/CVE-2011-1910.html" source="CVE"/>
        <description>Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:26.518-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:02.903-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:38.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23394 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.381-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:17.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:108085"/>
          <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:108637"/>
          <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:108793"/>
          <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:108632"/>
          <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:108750"/>
          <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:108867"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23393" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1333: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference ref_id="ELSA-2011:1333-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1333.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2426" ref_url="http://linux.oracle.com/cve/CVE-2011-2426.html" source="CVE"/>
        <reference ref_id="CVE-2011-2427" ref_url="http://linux.oracle.com/cve/CVE-2011-2427.html" source="CVE"/>
        <reference ref_id="CVE-2011-2428" ref_url="http://linux.oracle.com/cve/CVE-2011-2428.html" source="CVE"/>
        <reference ref_id="CVE-2011-2429" ref_url="http://linux.oracle.com/cve/CVE-2011-2429.html" source="CVE"/>
        <reference ref_id="CVE-2011-2430" ref_url="http://linux.oracle.com/cve/CVE-2011-2430.html" source="CVE"/>
        <reference ref_id="CVE-2011-2444" ref_url="http://linux.oracle.com/cve/CVE-2011-2444.html" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:34.709-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:02.727-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:38.679-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23393 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.966-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:17.115-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:24:15.390-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:24:15.390-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el5" test_ref="oval:org.mitre.oval:tst:105361"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el6" test_ref="oval:org.mitre.oval:tst:105078"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23392" version="46" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0981: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2013:0981-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-0981.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-1682" ref_url="http://linux.oracle.com/cve/CVE-2013-1682.html" source="CVE"/>
        <reference ref_id="CVE-2013-1684" ref_url="http://linux.oracle.com/cve/CVE-2013-1684.html" source="CVE"/>
        <reference ref_id="CVE-2013-1685" ref_url="http://linux.oracle.com/cve/CVE-2013-1685.html" source="CVE"/>
        <reference ref_id="CVE-2013-1686" ref_url="http://linux.oracle.com/cve/CVE-2013-1686.html" source="CVE"/>
        <reference ref_id="CVE-2013-1687" ref_url="http://linux.oracle.com/cve/CVE-2013-1687.html" source="CVE"/>
        <reference ref_id="CVE-2013-1690" ref_url="http://linux.oracle.com/cve/CVE-2013-1690.html" source="CVE"/>
        <reference ref_id="CVE-2013-1692" ref_url="http://linux.oracle.com/cve/CVE-2013-1692.html" source="CVE"/>
        <reference ref_id="CVE-2013-1693" ref_url="http://linux.oracle.com/cve/CVE-2013-1693.html" source="CVE"/>
        <reference ref_id="CVE-2013-1694" ref_url="http://linux.oracle.com/cve/CVE-2013-1694.html" source="CVE"/>
        <reference ref_id="CVE-2013-1697" ref_url="http://linux.oracle.com/cve/CVE-2013-1697.html" source="CVE"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:38.866-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:02.472-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:38.193-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23392 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:14.642-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:16.802-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:23:44.388-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:23:44.388-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:106651"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:107383"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:107554"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:107304"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:107235"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:107258"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23391" version="41" class="patch">
      <metadata>
        <title>ELSA-2010:0861: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference ref_id="ELSA-2010:0861-02" ref_url="http://linux.oracle.com/errata/ELSA-2010-0861.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3175" ref_url="http://linux.oracle.com/cve/CVE-2010-3175.html" source="CVE"/>
        <reference ref_id="CVE-2010-3176" ref_url="http://linux.oracle.com/cve/CVE-2010-3176.html" source="CVE"/>
        <reference ref_id="CVE-2010-3177" ref_url="http://linux.oracle.com/cve/CVE-2010-3177.html" source="CVE"/>
        <reference ref_id="CVE-2010-3178" ref_url="http://linux.oracle.com/cve/CVE-2010-3178.html" source="CVE"/>
        <reference ref_id="CVE-2010-3179" ref_url="http://linux.oracle.com/cve/CVE-2010-3179.html" source="CVE"/>
        <reference ref_id="CVE-2010-3180" ref_url="http://linux.oracle.com/cve/CVE-2010-3180.html" source="CVE"/>
        <reference ref_id="CVE-2010-3182" ref_url="http://linux.oracle.com/cve/CVE-2010-3182.html" source="CVE"/>
        <reference ref_id="CVE-2010-3183" ref_url="http://linux.oracle.com/cve/CVE-2010-3183.html" source="CVE"/>
        <reference ref_id="CVE-2010-3765" ref_url="http://linux.oracle.com/cve/CVE-2010-3765.html" source="CVE"/>
        <description>Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:32.770-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:02.253-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:37.854-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23391 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:10.760-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:16.471-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.12-1.el6_0" test_ref="oval:org.mitre.oval:tst:108086"/>
          <criterion comment="xulrunner is earlier than 0:1.9.2.12-1.el6_0" test_ref="oval:org.mitre.oval:tst:107466"/>
          <criterion comment="firefox is earlier than 0:3.6.12-1.el6_0" test_ref="oval:org.mitre.oval:tst:108116"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23390" version="14" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:1263: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference ref_id="ELSA-2012:1263-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-1263.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-3488" ref_url="http://linux.oracle.com/cve/CVE-2012-3488.html" source="CVE"/>
        <reference ref_id="CVE-2012-3489" ref_url="http://linux.oracle.com/cve/CVE-2012-3489.html" source="CVE"/>
        <description>The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:24:39.191-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:02.093-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:37.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23390 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:16.815-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:16.312-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:23:00.983-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:23:00.983-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106554"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106300"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:105880"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106563"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106713"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106599"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106525"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106664"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106690"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106826"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106734"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:106818"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="postgresql is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106643"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106841"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106823"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106350"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:105953"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106882"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106639"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106850"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:105897"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:106669"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23389" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0546: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2012:0546-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0546.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-1823" ref_url="http://linux.oracle.com/cve/CVE-2012-1823.html" source="CVE"/>
        <description>sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:20:03.959-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:01.862-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:37.419-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23389 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:16.105-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:16.123-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:21:19.315-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:21:19.315-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-common is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105943"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106247"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105747"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105657"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106216"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105572"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105521"/>
            <criterion comment="php is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106096"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105902"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106272"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106146"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106126"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105767"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106034"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106248"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106138"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106111"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:106217"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:105823"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106073"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106110"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106202"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106268"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105973"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105611"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105295"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106280"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106115"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106261"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106020"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105978"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106130"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106277"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106102"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105711"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106266"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105485"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106090"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105608"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105866"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106145"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106245"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106075"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:105382"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:106024"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23387" version="13" class="patch">
      <metadata>
        <title>ELSA-2010:0924: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference ref_id="ELSA-2010:0924-01" ref_url="http://linux.oracle.com/errata/ELSA-2010-0924.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-3445" ref_url="http://linux.oracle.com/cve/CVE-2010-3445.html" source="CVE"/>
        <reference ref_id="CVE-2010-4300" ref_url="http://linux.oracle.com/cve/CVE-2010-4300.html" source="CVE"/>
        <description>Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an LDSS packet with a long digest line that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:21:30.262-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:01.426-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:36.490-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23387 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.715-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:15.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="wireshark is earlier than 0:1.2.13-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108103"/>
          <criterion comment="wireshark-devel is earlier than 0:1.2.13-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:108273"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.2.13-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:107974"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23385" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:0250: elinks security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>elinks</product>
        </affected>
        <reference ref_id="ELSA-2013:0250-01" ref_url="http://linux.oracle.com/errata/ELSA-2013-0250.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-4545" ref_url="http://linux.oracle.com/cve/CVE-2012-4545.html" source="CVE"/>
        <description>The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:27:00.115-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:01.287-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:36.237-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23385 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.248-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:15.300-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:18:27.563-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:18:27.563-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <criterion comment="elinks is earlier than 0:0.12-0.21.pre5.el6_3" test_ref="oval:org.mitre.oval:tst:107140"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="elinks is earlier than 0:0.11.1-8.el5_9" test_ref="oval:org.mitre.oval:tst:107077"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23384" version="65" class="patch">
      <metadata>
        <title>ELSA-2011:0498: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="ELSA-2011:0498-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0498.html" source="VENDOR"/>
        <reference ref_id="CVE-2010-4250" ref_url="http://linux.oracle.com/cve/CVE-2010-4250.html" source="CVE"/>
        <reference ref_id="CVE-2010-4565" ref_url="http://linux.oracle.com/cve/CVE-2010-4565.html" source="CVE"/>
        <reference ref_id="CVE-2010-4649" ref_url="http://linux.oracle.com/cve/CVE-2010-4649.html" source="CVE"/>
        <reference ref_id="CVE-2011-0006" ref_url="http://linux.oracle.com/cve/CVE-2011-0006.html" source="CVE"/>
        <reference ref_id="CVE-2011-0711" ref_url="http://linux.oracle.com/cve/CVE-2011-0711.html" source="CVE"/>
        <reference ref_id="CVE-2011-0712" ref_url="http://linux.oracle.com/cve/CVE-2011-0712.html" source="CVE"/>
        <reference ref_id="CVE-2011-0726" ref_url="http://linux.oracle.com/cve/CVE-2011-0726.html" source="CVE"/>
        <reference ref_id="CVE-2011-1013" ref_url="http://linux.oracle.com/cve/CVE-2011-1013.html" source="CVE"/>
        <reference ref_id="CVE-2011-1016" ref_url="http://linux.oracle.com/cve/CVE-2011-1016.html" source="CVE"/>
        <reference ref_id="CVE-2011-1019" ref_url="http://linux.oracle.com/cve/CVE-2011-1019.html" source="CVE"/>
        <reference ref_id="CVE-2011-1044" ref_url="http://linux.oracle.com/cve/CVE-2011-1044.html" source="CVE"/>
        <reference ref_id="CVE-2011-1079" ref_url="http://linux.oracle.com/cve/CVE-2011-1079.html" source="CVE"/>
        <reference ref_id="CVE-2011-1080" ref_url="http://linux.oracle.com/cve/CVE-2011-1080.html" source="CVE"/>
        <reference ref_id="CVE-2011-1093" ref_url="http://linux.oracle.com/cve/CVE-2011-1093.html" source="CVE"/>
        <reference ref_id="CVE-2011-1573" ref_url="http://linux.oracle.com/cve/CVE-2011-1573.html" source="CVE"/>
        <description>net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to cause a denial of service (OOPS) via crafted packet data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:28.040-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.964-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:35.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23384 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.264-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:14.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108815"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108440"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108846"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108780"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108588"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108844"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108321"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108724"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108731"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108837"/>
          <criterion comment="kernel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:108110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23383" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1160: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>dhcp</product>
        </affected>
        <reference ref_id="ELSA-2011:1160-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1160.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2748" ref_url="http://linux.oracle.com/cve/CVE-2011-2748.html" source="CVE"/>
        <reference ref_id="CVE-2011-2749" ref_url="http://linux.oracle.com/cve/CVE-2011-2749.html" source="CVE"/>
        <description>The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:13:15.410-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.869-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:35.466-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23383 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.777-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:14.659-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="libdhcp4client is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:105185"/>
            <criterion comment="dhclient is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:105088"/>
            <criterion comment="dhcp-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:104771"/>
            <criterion comment="dhcp is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:104322"/>
            <criterion comment="libdhcp4client-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:105315"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="dhclient is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105282"/>
            <criterion comment="dhcp-devel is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:105103"/>
            <criterion comment="dhcp is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:104731"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23382" version="45" class="patch">
      <metadata>
        <title>ELSA-2012:0388: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2012:0388-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0388.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-0451" ref_url="http://linux.oracle.com/cve/CVE-2012-0451.html" source="CVE"/>
        <reference ref_id="CVE-2012-0455" ref_url="http://linux.oracle.com/cve/CVE-2012-0455.html" source="CVE"/>
        <reference ref_id="CVE-2012-0456" ref_url="http://linux.oracle.com/cve/CVE-2012-0456.html" source="CVE"/>
        <reference ref_id="CVE-2012-0457" ref_url="http://linux.oracle.com/cve/CVE-2012-0457.html" source="CVE"/>
        <reference ref_id="CVE-2012-0458" ref_url="http://linux.oracle.com/cve/CVE-2012-0458.html" source="CVE"/>
        <reference ref_id="CVE-2012-0459" ref_url="http://linux.oracle.com/cve/CVE-2012-0459.html" source="CVE"/>
        <reference ref_id="CVE-2012-0460" ref_url="http://linux.oracle.com/cve/CVE-2012-0460.html" source="CVE"/>
        <reference ref_id="CVE-2012-0461" ref_url="http://linux.oracle.com/cve/CVE-2012-0461.html" source="CVE"/>
        <reference ref_id="CVE-2012-0462" ref_url="http://linux.oracle.com/cve/CVE-2012-0462.html" source="CVE"/>
        <reference ref_id="CVE-2012-0464" ref_url="http://linux.oracle.com/cve/CVE-2012-0464.html" source="CVE"/>
        <description>Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:19:54.502-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.656-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:35.050-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23382 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:11.567-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:14.328-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:106065"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:106038"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23381" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2014:0133: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference ref_id="ELSA-2014:0133-00" ref_url="http://linux.oracle.com/errata/ELSA-2014-0133.html" source="VENDOR"/>
        <reference ref_id="CVE-2014-1477" ref_url="http://linux.oracle.com/cve/CVE-2014-1477.html" source="CVE"/>
        <reference ref_id="CVE-2014-1479" ref_url="http://linux.oracle.com/cve/CVE-2014-1479.html" source="CVE"/>
        <reference ref_id="CVE-2014-1481" ref_url="http://linux.oracle.com/cve/CVE-2014-1481.html" source="CVE"/>
        <reference ref_id="CVE-2014-1482" ref_url="http://linux.oracle.com/cve/CVE-2014-1482.html" source="CVE"/>
        <reference ref_id="CVE-2014-1486" ref_url="http://linux.oracle.com/cve/CVE-2014-1486.html" source="CVE"/>
        <reference ref_id="CVE-2014-1487" ref_url="http://linux.oracle.com/cve/CVE-2014-1487.html" source="CVE"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:34:07.589-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.495-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:34.748-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23381 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:13.947-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:14.101-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:17:56.051-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:17:56.051-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:107948"/>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:107814"/>
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23380" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1852: krb5-appl security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>krb5-appl</product>
        </affected>
        <reference ref_id="ELSA-2011:1852-02" ref_url="http://linux.oracle.com/errata/ELSA-2011-1852.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4862" ref_url="http://linux.oracle.com/cve/CVE-2011-4862.html" source="CVE"/>
        <description>Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:31:08.735-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.435-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:34.650-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23380 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.387-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:13.939-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="krb5-appl-clients is earlier than 0:1.0.1-7.el6_2" test_ref="oval:org.mitre.oval:tst:109666"/>
          <criterion comment="krb5-appl-servers is earlier than 0:1.0.1-7.el6_2" test_ref="oval:org.mitre.oval:tst:109750"/>
          <criterion comment="krb5-appl is earlier than 0:1.0.1-7.el6_2" test_ref="oval:org.mitre.oval:tst:109198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23379" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2012:0699: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2012:0699-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0699.html" source="VENDOR"/>
        <reference ref_id="CVE-2012-2333" ref_url="http://linux.oracle.com/cve/CVE-2012-2333.html" source="CVE"/>
        <description>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:22:15.692-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.342-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:34.532-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23379 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.479-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:13.833-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:17:24.586-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:17:24.586-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:106317"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:106166"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:105947"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:105544"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:106019"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:106238"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:105827"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23378" version="30" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2011:1241: ecryptfs-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 5</platform>
          <platform>Oracle Linux 6</platform>
          <product>ecryptfs-utils</product>
        </affected>
        <reference ref_id="ELSA-2011:1241-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1241.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-1831" ref_url="http://linux.oracle.com/cve/CVE-2011-1831.html" source="CVE"/>
        <reference ref_id="CVE-2011-1832" ref_url="http://linux.oracle.com/cve/CVE-2011-1832.html" source="CVE"/>
        <reference ref_id="CVE-2011-1834" ref_url="http://linux.oracle.com/cve/CVE-2011-1834.html" source="CVE"/>
        <reference ref_id="CVE-2011-1835" ref_url="http://linux.oracle.com/cve/CVE-2011-1835.html" source="CVE"/>
        <reference ref_id="CVE-2011-1837" ref_url="http://linux.oracle.com/cve/CVE-2011-1837.html" source="CVE"/>
        <reference ref_id="CVE-2011-3145" ref_url="http://linux.oracle.com/cve/CVE-2011-3145.html" source="CVE"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.	When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:15:22.667-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:00.173-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:34.221-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23378 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.219-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:13.594-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:16:34.088-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:16:34.088-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:105081"/>
            <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:105323"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:104371"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:105142"/>
            <criterion comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:105186"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:105099"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23376" version="13" class="patch">
      <metadata>
        <title>ELSA-2011:1088: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference ref_id="ELSA-2011:1088-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1088.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-2502" ref_url="http://linux.oracle.com/cve/CVE-2011-2502.html" source="CVE"/>
        <reference ref_id="CVE-2011-2503" ref_url="http://linux.oracle.com/cve/CVE-2011-2503.html" source="CVE"/>
        <description>The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:28:18.011-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:59.491-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:32.993-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23376 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:12.815-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:12.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="systemtap-runtime is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:108593"/>
          <criterion comment="systemtap-client is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:108597"/>
          <criterion comment="systemtap-testsuite is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:109015"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:108656"/>
          <criterion comment="systemtap is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:108895"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:109107"/>
          <criterion comment="systemtap-grapher is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:108478"/>
          <criterion comment="systemtap-server is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:109201"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23375" version="6" class="patch">
      <metadata>
        <title>ELSA-2011:1409: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference ref_id="ELSA-2011:1409-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-1409.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-3207" ref_url="http://linux.oracle.com/cve/CVE-2011-3207.html" source="CVE"/>
        <description>crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:30:57.480-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:59.426-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:32.891-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23375 - optimisation of Oracle Linux content" date="2014-05-05T17:41:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:43:15.803-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:12.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="openssl-devel is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:109468"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:109319"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:109479"/>
          <criterion comment="openssl is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:109353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23373" version="25" class="patch">
      <metadata>
        <title>ELSA-2011:0413: glibc security update (Important)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference ref_id="ELSA-2011:0413-01" ref_url="http://linux.oracle.com/errata/ELSA-2011-0413.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-0536" ref_url="http://linux.oracle.com/cve/CVE-2011-0536.html" source="CVE"/>
        <reference ref_id="CVE-2011-1071" ref_url="http://linux.oracle.com/cve/CVE-2011-1071.html" source="CVE"/>
        <reference ref_id="CVE-2011-1095" ref_url="http://linux.oracle.com/cve/CVE-2011-1095.html" source="CVE"/>
        <reference ref_id="CVE-2011-1658" ref_url="http://linux.oracle.com/cve/CVE-2011-1658.html" source="CVE"/>
        <reference ref_id="CVE-2011-1659" ref_url="http://linux.oracle.com/cve/CVE-2011-1659.html" source="CVE"/>
        <description>Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:25:32.275-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:59.193-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:32.481-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23373 - optimisation of Oracle Linux content" date="2014-07-03T11:23:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-03T11:29:18.946-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:00:56.476-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="glibc-utils is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:108441"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:108177"/>
          <criterion comment="glibc is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:108742"/>
          <criterion comment="nscd is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:108715"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:108522"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:108531"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:108770"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23372" version="6" class="patch">
      <metadata>
        <title>ELSA-2012:0069: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference ref_id="ELSA-2012:0069-01" ref_url="http://linux.oracle.com/errata/ELSA-2012-0069.html" source="VENDOR"/>
        <reference ref_id="CVE-2011-4815" ref_url="http://linux.oracle.com/cve/CVE-2011-4815.html" source="CVE"/>
        <description>Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T10:33:08.354-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:59.120-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:32.364-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23372 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:51.041-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:12.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
        <criteria operator="OR" comment="rpm test">
          <criterion comment="ruby is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:109648"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:109841"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:109641"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:109511"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:109439"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:109868"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:109872"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:109712"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:109207"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23370" version="7" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: ELSA-2013:1049: php security update (Critical)</title>
        <affected family="unix">
          <platform>Oracle Linux 6</platform>
          <platform>Oracle Linux 5</platform>
          <product>php</product>
        </affected>
        <reference ref_id="ELSA-2013:1049-00" ref_url="http://linux.oracle.com/errata/ELSA-2013-1049.html" source="VENDOR"/>
        <reference ref_id="CVE-2013-4113" ref_url="http://linux.oracle.com/cve/CVE-2013-4113.html" source="CVE"/>
        <description>ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-13T12:30:04.000-05:00">
              <contributor organization="Hewlett-Packard">Vinay Naikar</contributor>
            </submitted>
            <status_change date="2014-03-18T09:29:50.250-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:04:58.877-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:04:32.023-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23370 - optimisation of Oracle Linux content" date="2014-05-05T17:43:00.345-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-05T17:44:50.137-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:04:11.777-04:00">ACCEPTED</status_change>
            <modified comment="Deprecate duplicates in Oracle Linux patches." date="2014-07-11T17:15:45.833-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-11T17:15:45.833-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="rpm test">
          <extend_definition comment="Oracle Linux 6.x" definition_ref="oval:org.mitre.oval:def:16594"/>
          <criteria operator="OR" comment="rpm test">
            <criterion comment="php-embedded is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107656"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107142"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107613"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107306"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107335"/>
            <criterion comment="php is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107479"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107620"/>
            <criterion comment="php-process is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:107707"/>
 